Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

During a security event, an Endpoint Detection and Response (EDR) agent deployed on a critical file server detects suspicious rapid file modification patterns consistent with ransomware activity. Arrange the following EDR incident containment and response steps in the correct sequential order from first to last.

  1. 1Ingest and triage the initial EDR behavioral alert identifying suspicious process activity and rapid file modifications.
  2. 2Initiate network isolation of the affected host through the EDR agent console to stop command-and-control communication and lateral spread.
  3. 3Capture volatile process memory for forensic analysis and terminate the malicious parent and child process trees.
  4. 4Quarantine identified malicious artifacts and execute EDR file remediation and rollback controls.
  5. 5Perform a comprehensive telemetry scan to verify system integrity and restore normal network connectivity.

Cevap

The correct response sequence begins with ingesting and triaging the initial EDR alert, followed immediately by initiating agent-based network isolation to prevent lateral movement. Next, volatile memory is captured and active malicious processes are killed. Following host containment, malicious files are quarantined and modified files are remediated. Finally, a complete system integrity scan is completed before restoring network connectivity.
The standard EDR containment workflow prioritizes rapid threat isolation to prevent lateral movement, followed by volatile evidence preservation, malicious process termination, file quarantine/remediation, and finally health verification prior to restoring network access.

Adım Adım Çözüm

1
Identify and validate threat telemetry
Alert triage confirms active ransomware behavior on the endpoint.
Detection and triage must precede any intervention to verify the scope of the alert.
2
Enforce host isolation via EDR agent
The host is logically isolated from the network while preserving EDR agent management channels.
Immediate containment stops command-and-control (C2) communication and prevents lateral movement across the enterprise.
3
Dump volatile memory and terminate malicious processes
RAM artifacts are saved for forensic examination and execution of the attack payload is halted.
Capturing memory prior to process termination ensures critical volatile evidence is preserved.
4
Quarantine binaries and execute rollback remediation
Malicious code is removed and modified system files are restored from clean snapshots.
Eradication eliminates host artifacts and restores compromised assets to a known good state.
5
Validate endpoint health and un-isolate host
System cleanliness is verified and full network access is safely re-established.
Reconnection to the network should only occur after verified remediation.

Anahtar Kavram

Endpoint Detection and Response (EDR) Incident Containment Workflow
Bu soruyu puanla