Soru

Zorluk: KolayIncident Response Process and Playbooks

An incident response team discovers a server on the enterprise network actively communicating with a known malicious command-and-control server following a ransomware infection. According to standard incident response playbooks for the containment phase, which of the following actions should the analyst perform immediately? (Select TWO.)

  1. Disconnect the network interface of the affected server.Cevap
  2. Capture the volatile system memory (RAM) for forensic examination.Cevap
  3. C
    Re-image the server operating system and restore from the latest offline backup.
  4. D
    Conduct a post-incident review meeting with executive leadership.

Cevap

Disconnecting the network interface of the affected server and capturing volatile system memory (RAM).
During the containment phase of incident response, the primary objectives are limiting the scope of damage and preserving volatile evidence. Disconnecting the server's network interface halts communication with command-and-control servers and prevents lateral spread across the network. Capturing system RAM preserves crucial volatile evidence, such as encryption keys, active connections, and memory-resident malware payloads, before the system state is modified.

Adım Adım Çözüm

1
Identify the current lifecycle phase
The incident is actively occurring, placing the current response effort squarely in the Containment phase.
Containment actions focus on preventing further damage and lateral movement while preserving evidence.
2
Select immediate network containment
Isolating the system stops active C2 traffic and lateral spread.
Physical or virtual network disconnection isolates the threat without destroying evidence in RAM.
3
Preserve volatile evidence
RAM contents are captured prior to system reboot or power-down.
Volatile memory contains transient threat artifacts that are lost upon system shutdown.

Anahtar Kavram

Incident Response Containment Phase Actions
Bu soruyu puanla