Soru

Zorluk: ZorEndpoint Detection and Response (EDR)

An enterprise infrastructure team discovers that an infected internal workstation executed fileless malware that established an encrypted outbound connection to an external command-and-control server. Traditional signature-based antivirus and perimeter firewalls failed to identify or restrict the malicious activity. To contain the active compromise immediately while ensuring SOC analysts retain remote telemetry collection and administrative management access to the host, which of the following Endpoint Detection and Response (EDR) capabilities should be executed?

  1. Initiate host-level network isolation with console management exemptionsCevap
  2. B
    Reconfigure edge firewall egress filtering to block suspicious destination IP addresses
  3. C
    Deploy updated static definition files to the legacy endpoint antivirus engine
  4. D
    Create host firewall rules to drop all inbound traffic on administrative service ports

Cevap

Initiate host-level network isolation with console management exemptions
Host-level network isolation applied by an EDR agent restricts all network traffic to and from the infected endpoint, blocking outbound C2 beacons and preventing lateral movement. Crucially, EDR agents maintain an explicit channel exemption for management traffic back to the cloud or on-premises security console, allowing analysts to perform remote remediation and forensic triage.

Adım Adım Çözüm

1
Analyze the incident requirements
Identified the need to instantly halt outbound command-and-control (C2) activity and internal lateral movement from a compromised host while keeping remote forensic and management connectivity intact.
Containment must occur at the endpoint layer without blinding security operations analysts.
2
Evaluate EDR containment mechanisms versus legacy defenses
Determined that host-level network isolation enforces software-defined isolation on the endpoint network stack.
Perimeter firewalls cannot stop internal lateral movement, and signature updates cannot contain active fileless threats.
3
Verify EDR console communication persistence
Confirmed that EDR host isolation policies explicitly preserve the agent-to-console management tunnel.
Analyst access to endpoint telemetry and automated playbook execution relies on maintaining this isolated management connection.

Anahtar Kavram

Endpoint Detection and Response (EDR) Host Isolation
Tahmini Süre:1m 30s
Bu soruyu puanla