Soru

Zorluk: OrtaIncident Response Process and Playbooks

A security analyst in a Security Operations Center (SOC) confirms that a workstation in the accounting department is infected with active ransomware. Network monitoring logs indicate the infected host is currently attempting to scan and encrypt remote file shares over SMB across the local subnet. Which of the following actions should the analyst perform FIRST according to standard incident response process playbooks?

  1. Disconnect the infected workstation from the network by disabling its network interface or placing it into an isolated quarantine VLAN.Cevap
  2. B
    Reimage the host operating system and restore affected user directories from the most recent offline backup.
  3. C
    Terminate the malicious ransomware processes and delete the associated executable files and startup registry keys.
  4. D
    Implement a global firewall policy to block all internal SMB port 445 traffic across the enterprise network.

Cevap

Disconnect the infected workstation from the network by disabling its network interface or placing it into an isolated quarantine VLAN.
Disconnecting the host from the network executes the containment phase of the incident response lifecycle. Immediate containment prevents the active ransomware from spreading laterally across SMB network shares, mitigating further operational damage.

Adım Adım Çözüm

1
Analyze the incident status from the scenario
Detection and analysis are complete; an active ransomware infection and lateral movement attempt via SMB are confirmed.
Determining the current phase dictates which playbook step must follow immediately.
2
Identify the immediate lifecycle requirement
Containment is required to halt further damage and prevent lateral spread to adjacent network storage.
Standard NIST (SP 800-61) and ISO incident handling playbooks mandate containment before moving to eradication or recovery.
3
Select the effective containment control
Isolating the specific workstation (via host network interface disablement or quarantine VLAN assignment) stops SMB traffic without causing unnecessary enterprise disruption.
Host isolation limits the blast radius of the ransomware while preserving evidence for forensic review.

Anahtar Kavram

Incident Response Lifecycle Phases and Containment Playbooks
Tahmini Süre:1m 15s
Bu soruyu puanla