A security analyst notices suspicious process execution on a financial department workstation during an active malware outbreak. To immediately block the workstation's network communication with other internal systems while preserving the security team's remote telemetry and control channel, which of the following is the most appropriate action to take?
- Perform a network host isolation action through the EDR consoleCevap
- BModify ingress rules on the enterprise border firewall to block internal host traffic
- CPush an updated signature file to legacy antivirus software on the local subnet
- DReassign the host system logging policy to a detective control classification
Cevap
Perform a network host isolation action through the EDR console
Executing a host isolation feature via an EDR platform severs all network traffic to and from the targeted workstation except for the encrypted connection between the EDR agent and its management console. This effectively stops lateral movement while enabling continuous incident investigation.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Network Isolation