An incident response team discovers a server on the enterprise network actively communicating with a known malicious command-and-control server following a ransomware infection. According to standard incident response playbooks for the containment phase, which of the following actions should the analyst perform immediately? (Select TWO.)
- Disconnect the network interface of the affected server.Cevap
- Capture the volatile system memory (RAM) for forensic examination.Cevap
- CRe-image the server operating system and restore from the latest offline backup.
- DConduct a post-incident review meeting with executive leadership.
Cevap
Disconnecting the network interface of the affected server and capturing volatile system memory (RAM).
During the containment phase of incident response, the primary objectives are limiting the scope of damage and preserving volatile evidence. Disconnecting the server's network interface halts communication with command-and-control servers and prevents lateral spread across the network. Capturing system RAM preserves crucial volatile evidence, such as encryption keys, active connections, and memory-resident malware payloads, before the system state is modified.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Phase Actions