A security analyst receives an alert showing suspicious process activity and memory execution on an enterprise host. Which of the following actions can the analyst perform directly through an Endpoint Detection and Response (EDR) agent to immediately contain and investigate the host? (Select TWO.)
- Isolate the compromised host from the network while maintaining agent management connectivity.Cevap
- BModify perimeter firewall access control lists to block outbound internet traffic.
- Terminate running malicious processes and process trees remotely on the endpoint.Cevap
- DPhysically replace the host network interface card to prevent hardware spoofing.
Cevap
The analyst can isolate the compromised host from the network while maintaining agent management connectivity, and terminate running malicious processes remotely on the endpoint.
Endpoint Detection and Response (EDR) agents provide direct host-level control. Isolating the endpoint restricts lateral movement while keeping command telemetry active, and terminating malicious processes stops unauthorized code execution in host memory.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) host isolation and process termination capabilities