Soru

Zorluk: OrtaIncident Response Process and Playbooks

A Security Operations Center (SOC) analyst detects lateral movement across several workstation subnets. Further analysis reveals that an attacker is using compromised domain administrator credentials to remotely execute malicious scripts and establish persistent connections. The organization initiates its incident response playbook and moves into the containment phase. Which TWO of the following immediate actions should the incident response team execute during this phase?

  1. Disconnect affected host workstations from the network via host isolation commands while keeping systems powered on.Cevap
  2. Revoke active Kerberos ticket-granting tokens and temporarily disable the compromised administrator account.Cevap
  3. C
    Re-image the compromised host workstations immediately using clean baseline gold images.
  4. D
    Reconfigure perimeter firewalls to convert preventive filtering rules into detective honeypot capture mechanisms.

Cevap

The incident response team should disconnect affected host workstations from the network via host isolation while keeping them powered on, and revoke active Kerberos ticket-granting tokens while temporarily disabling the compromised administrator account.
In accordance with standard NIST incident response guidelines, containment focuses on stopping the spread of an incident and mitigating active threat vectors. Network host isolation stops lateral movement across subnets while preserving RAM for forensics, and disabling compromised administrative credentials prevents further unauthorized authentication.

Adım Adım Çözüm

1
Identify containment objectives for lateral movement and compromised identity attack vectors.
The primary goals in containment are isolating affected segments to prevent blast radius expansion and cutting off active compromised identity sessions without destroying evidence.
Containment limits damage while maintaining forensic volatility integrity.
2
Evaluate network and host containment measures.
Disconnecting affected endpoints via host-based software controls isolates the system from communicating with other internal assets while preserving volatile memory state.
Host network isolation blocks lateral traffic without powering off devices.
3
Evaluate identity containment measures.
Revoking active session tokens and disabling compromised user accounts stops credential abuse immediately across the directory domain.
Attackers using valid administrative credentials will lose access immediately across network services.

Anahtar Kavram

Incident Response Containment Tactics and Volatility Preservation
Bu soruyu puanla