A Security Operations Center (SOC) analyst receives a high-severity alert indicating that an industrial control system (ICS) building automation gateway has initiated unauthorized outbound encrypted connections to a known malicious external IP address. The analyst confirms that unauthorized administrative access occurred and malicious code is actively running on the gateway. According to the NIST Incident Response Framework, which action should the responder perform FIRST?
- Apply an isolated quarantine VLAN profile to the connected switch port to halt external communications.Cevap
- BFlash the gateway with vendor-certified firmware and restore system settings from a verified backup.
- CConduct a post-incident lessons learned session to update the facility access control incident playbook.
- DPower off the physical gateway immediately to ensure evidence is locked in permanent storage.
Cevap
Apply an isolated quarantine VLAN profile to the connected switch port to halt external communications.
According to the NIST Incident Response Framework (SP 800-61), once an incident is detected and confirmed, responders must immediately move to the Containment phase. Placing the switch port into an isolated quarantine VLAN stops command-and-control (C2) communication and lateral movement while keeping the system powered on so volatile memory can be preserved for forensics.
Adım Adım Çözüm
Anahtar Kavram
NIST Incident Response Lifecycle (Containment Phase)