Soru

Zorluk: KolayIncident Response Process and Playbooks

During a routine operational monitoring check, a system administrator confirms that a workstation in the assembly plant was infected with malware after a user inserted an unauthorized flash drive. The incident response team has just validated the active incident. According to standard NIST/ISO incident response frameworks, which action should the responder execute FIRST during the containment phase?

  1. Disconnect the infected workstation from the network segment to isolate the device.Cevap
  2. B
    Wipe the hard drive and restore the operating system from a verified clean backup image.
  3. C
    Convene the incident response team for a lessons-learned session to update security policies.
  4. D
    Implement a preventive perimeter firewall rule to block future incoming USB connections.

Cevap

Disconnect the infected workstation from the network segment to isolate the device.
In standard incident response playbooks, the immediate priority upon confirming a malware infection is containment. Disconnecting the affected host isolates the endpoint and prevents lateral propagation across adjacent network resources.

Adım Adım Çözüm

1
Determine the current phase in the incident response lifecycle.
The incident has just been confirmed, placing the team at the beginning of the Containment phase.
Containment limits the scope of impact before permanent remediation steps are undertaken.
2
Identify the primary containment objective for an infected host.
Network isolation prevents lateral movement and external command-and-control activity.
Stopping malware spread takes precedence over eradication, recovery, or post-incident review.

Anahtar Kavram

Incident Response Process and Playbooks
Bu soruyu puanla