Soru

Zorluk: OrtaIncident Response Process and Playbooks

After detecting an active fileless malware infection executing via host memory scripts on a critical workstation, the Incident Response (IR) team initiates their initial handling playbook. Which of the following actions should the team perform immediately to contain the threat while preserving digital evidence? (Select TWO.)

  1. Disconnect the workstation from the local network via physical cable removal or port isolation while keeping system power on.Cevap
  2. Acquire a full forensic capture of the host system's volatile memory (RAM) prior to any system shutdown or state modification.Cevap
  3. C
    Immediately reboot the host workstation into safe mode to stop active malicious process execution.
  4. D
    Re-image the workstation operating system using an enterprise golden master image.

Cevap

The incident response team should isolate the host from the network while maintaining system power, and capture a full dump of volatile system memory (RAM).
Effective incident response playbooks mandate network isolation to stop threat expansion while keeping the machine powered on, followed by acquiring volatile RAM to capture memory-resident fileless payloads according to the order of volatility.

Adım Adım Çözüm

1
Evaluate containment priorities during an active fileless malware incident.
Identify that network containment is essential to stop lateral movement and Command & Control (C2) communication without powering off the host.
Maintaining system power prevents volatile memory loss.
2
Apply forensic evidence preservation principles according to the order of volatility.
Prioritize capturing volatile system RAM before performing host changes, reboots, or drive imaging.
Fileless malware resides exclusively in memory and is wiped if the system reboots.
3
Distinguish containment phase steps from eradication and recovery actions.
Reject premature re-imaging or host wiping actions.
Re-imaging occurs in the eradication phase after evidence collection and root cause analysis are finished.

Anahtar Kavram

Incident Response Containment and Order of Volatility in Evidence Preservation
Tahmini Süre:1m 30s
Bu soruyu puanla