During a routine operational monitoring check, a system administrator confirms that a workstation in the assembly plant was infected with malware after a user inserted an unauthorized flash drive. The incident response team has just validated the active incident. According to standard NIST/ISO incident response frameworks, which action should the responder execute FIRST during the containment phase?
- Disconnect the infected workstation from the network segment to isolate the device.Cevap
- BWipe the hard drive and restore the operating system from a verified clean backup image.
- CConvene the incident response team for a lessons-learned session to update security policies.
- DImplement a preventive perimeter firewall rule to block future incoming USB connections.
Cevap
Disconnect the infected workstation from the network segment to isolate the device.
In standard incident response playbooks, the immediate priority upon confirming a malware infection is containment. Disconnecting the affected host isolates the endpoint and prevents lateral propagation across adjacent network resources.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Process and Playbooks