Soru

Zorluk: KolayIncident Response Process and Playbooks

During an ongoing incident investigation, a security analyst detects that an unauthorized rogue laptop is actively transmitting encrypted data across an internal enterprise network. According to standard incident response frameworks, which of the following actions should the analyst perform FIRST?

  1. Disconnect the rogue laptop from the network to contain the incident.Cevap
  2. B
    Format the hard drive of the rogue laptop and restore the system image.
  3. C
    Schedule a lessons-learned meeting with the incident response team.
  4. D
    Implement preventive firewall rules for web application SQL injection attacks.

Cevap

Disconnect the rogue laptop from the network to contain the incident.
Disconnecting the rogue laptop immediately contains the threat by severing active network communication, preventing further unauthorized data exfiltration in accordance with standard incident response lifecycle guidelines.

Adım Adım Çözüm

1
Identify the current phase of the incident response process based on the scenario.
An active threat (rogue device transmitting data) has been detected, requiring immediate containment.
Containment limits the damage of an ongoing incident and prevents further unauthorized data transmission.
2
Select the action that corresponds to the containment phase.
Disconnecting or isolating the unauthorized device stops active communication immediately.
Containment must occur prior to performing eradication, recovery, or post-incident review.

Anahtar Kavram

Incident Response Lifecycle - Containment Phase
Bu soruyu puanla