A security analyst is executing an incident response playbook following a confirmed malware alert on a user workstation. Which of the following actions represent appropriate steps during the containment phase of the incident response process? (Select TWO.)
- Disconnecting the workstation from the network by disabling its network interfaceCevap
- Applying temporary ACLs at the perimeter firewall to block outbound communication to known malicious IP addressesCevap
- CReimaging the infected system's hard drive using a standard gold master image
- DHolding a post-incident review session with the incident response team to update playbook documentation
Cevap
The appropriate containment steps are disconnecting the workstation from the network by disabling its network interface and applying temporary firewall ACLs to block outbound communication to malicious command-and-control servers.
During the containment phase of incident response, the main priority is stopping the spread of the attack and limiting its impact. Disabling the local network interface isolates the system from internal network assets, stopping lateral movement. Blocking outbound traffic to command-and-control IP addresses prevents ongoing data exfiltration and remote attacker control.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Actions