A Security Operations Center (SOC) analyst receives a validated alert indicating unauthorized administrative credential usage and potential persistence mechanisms on a critical internal server. According to standard incident response frameworks and playbooks, the analyst must focus on immediate containment and evidence preservation. Which of the following actions should the analyst perform at this stage? (Select TWO.)
- Place the affected server into an isolated quarantine VLAN to prevent lateral movement while preserving volatile state.Cevap
- BWipe the hard drive immediately and reinstall the operating system using a golden image.
- Capture a full image of volatile memory (RAM) to preserve active network connections and running process artifacts.Cevap
- DConduct a formal post-incident lessons learned session to update the enterprise incident response playbook.
Cevap
The analyst should isolate the server on a quarantine VLAN and capture a full image of volatile memory (RAM).
Isolating the compromised host on a quarantine VLAN halts lateral network movement while keeping the system powered, allowing analysts to capture volatile memory (RAM) to preserve ephemeral evidence such as running processes and active sockets before it is lost.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment and Evidence Preservation Lifecycle Phases