An EDR console triggers a high-severity behavioral alert on an enterprise application server after detecting an obfuscated PowerShell execution that attempts process injection into a legitimate system process and initiates an outbound connection to an unknown external IP address. Which of the following initial containment and investigation actions should the security analyst perform directly using EDR console capabilities? (Select TWO.)
- Apply host-level network isolation to the endpoint while maintaining management channel connectivity.Cevap
- Kill the malicious process tree and capture a volatile memory dump for forensic analysis.Cevap
- CPush an updated static virus signature file to enterprise endpoints via legacy antivirus definitions.
- DReconfigure the perimeter firewall to drop all inbound and outbound traffic for the target subnet.
Cevap
The analyst should isolate the host endpoint from the network while preserving EDR management communications and terminate the suspicious process tree while capturing volatile memory for investigation.
Isolating the endpoint network traffic while retaining agent communication stops malicious lateral movement without severing SOC management, and terminating process trees alongside volatile memory acquisition halts code execution while preserving volatile evidence.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) Host Isolation and Process Containment
Tahmini Süre:1m 30s