A Security Operations Center (SOC) analyst receives a high-severity alert from a Wireless Intrusion Prevention System (WIPS) indicating that an unauthorized rogue access point has been connected to an internal network switch port. Which of the following sequence of steps represents the correct order for responding to this incident according to standard incident response playbooks?
- 1Validate the alert by analyzing switch port logs and netflow data to confirm the exact location and scope of the unauthorized connection.
- 2Logically isolate the affected switch port via network management tools to halt unauthorized wireless traffic.
- 3Physically remove the unauthorized access point and update Network Access Control (NAC) policies to prevent similar unauthorized attachments.
- 4Restore standard switch port settings and verify through network telemetry scans that system operations are operating securely.
- 5Conduct a post-incident review to document lessons learned and update physical security auditing procedures.
Cevap
The correct order of incident response actions is: 1) Validate the alert by analyzing switch port logs and netflow data; 2) Logically isolate the affected switch port via network management tools; 3) Physically remove the unauthorized access point and update NAC policies; 4) Restore standard switch port settings and verify network telemetry; 5) Conduct a post-incident review to document lessons learned.
Standard incident response frameworks (such as NIST SP 800-61) define a strict sequential process: Detection and Analysis (validating the WIPS alert via switch logs), Containment (logically isolating the switch port), Eradication (physically removing the rogue AP and updating NAC rules), Recovery (restoring switch port operation safely and monitoring telemetry), and Post-Incident Activity (conducting a lessons learned review).
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Phases (NIST SP 800-61)
Tahmini Süre:1m 30s