Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

Following an alert indicating that an unauthorized process attempted to dump LSASS memory on a corporate workstation, a security analyst needs to prevent the compromised host from communicating with internal network assets while preserving the host's active connection to the central EDR console for remote incident triage. Which of the following capabilities should the analyst execute?

  1. Host network isolationCevap
  2. B
    Edge firewall rule modification
  3. C
    Static antivirus signature update
  4. D
    Deception honeypot deployment on the local subnet

Cevap

Host network isolation is the appropriate EDR capability to stop lateral movement while retaining agent communication for incident triage.
Host network isolation configures the local software driver or agent to block all network traffic to and from the host, with an exception for the encrypted control channel to the EDR management platform. This effectively stops lateral movement across the enterprise while enabling security analysts to perform remote triage, memory dumps, and remediation actions.

Adım Adım Çözüm

1
Identify containment objectives during an active host compromise
The host must be restricted from communicating with other internal network systems.
Preventing lateral movement limits the spread of post-exploitation activities across the enterprise.
2
Evaluate EDR features that isolate endpoints while retaining management control
Host network isolation applies software-defined filtering at the endpoint level, dropping user-space and local network traffic while keeping the EDR telemetry socket open.
Security operations teams require uninterrupted telemetry access to collect volatile data and execute response playbooks remotely.

Anahtar Kavram

Endpoint Detection and Response (EDR) Host Network Isolation
Tahmini Süre:1m 0s
Bu soruyu puanla