Security telemetry indicates that an administrative workstation has executed an unauthorized script attempting to establish a reverse shell to an external command-and-control (C2) server and extract system credentials. Which of the following response actions should an analyst perform directly using the Endpoint Detection and Response (EDR) agent to contain the threat while preserving forensic evidence? (Select TWO.)
- Apply host network isolation through the EDR console to restrict network traffic exclusively to the security management channel.Cevap
- BReconfigure the edge firewall access control list to block outbound traffic from the entire local workstation subnet.
- Terminate the unauthorized process tree and quarantine the associated file artifacts using EDR response actions.Cevap
- DPerform an immediate hard power cycle of the system to clear volatile memory and stop script execution.
Cevap
The correct containment and remediation actions are applying host network isolation through the EDR console and terminating the unauthorized process tree while quarantining file artifacts via EDR response tools.
Applying host network isolation via EDR blocks lateral network movement and external C2 communications while keeping the system running to preserve volatile RAM. Terminating the process tree and quarantining malicious files neutralizes execution directly at the endpoint level via native agent capabilities.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) Containment and Remediation Controls