After detecting an active fileless malware infection executing via host memory scripts on a critical workstation, the Incident Response (IR) team initiates their initial handling playbook. Which of the following actions should the team perform immediately to contain the threat while preserving digital evidence? (Select TWO.)
- Disconnect the workstation from the local network via physical cable removal or port isolation while keeping system power on.Cevap
- Acquire a full forensic capture of the host system's volatile memory (RAM) prior to any system shutdown or state modification.Cevap
- CImmediately reboot the host workstation into safe mode to stop active malicious process execution.
- DRe-image the workstation operating system using an enterprise golden master image.
Cevap
The incident response team should isolate the host from the network while maintaining system power, and capture a full dump of volatile system memory (RAM).
Effective incident response playbooks mandate network isolation to stop threat expansion while keeping the machine powered on, followed by acquiring volatile RAM to capture memory-resident fileless payloads according to the order of volatility.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment and Order of Volatility in Evidence Preservation
Tahmini Süre:1m 30s