CompTIA Cloud+ (CV0-004)SecurityMedium
A security incident response team is investigating a potential data breach within a cloud environment. The team needs to quickly isolate the compromised virtual machines (VMs) to prevent further lateral movement and data exfiltration, while preserving their state for forensic analysis. Which of the following actions should the team prioritize?
- ARevert the compromised VMs to a previous known good state.
- BModify the network security group (NSG) rules to deny all inbound and outbound traffic to the compromised VMs.
- CTerminate the compromised VMs immediately.
- DCreate snapshots of the compromised VMs and then move them to an isolated network segment.
Show answer & explanationAnswer & explanation
Correct answer: B. Modify the network security group (NSG) rules to deny all inbound and outbound traffic to the compromised VMs.
Modifying NSG rules to deny all traffic isolates the VMs without altering their current state, which is crucial for forensic analysis. Terminating or reverting them would destroy evidence, and creating snapshots without isolation first still leaves them connected.
Why the other options are wrong
- A. Reverting VMs would destroy evidence of the current compromise and make forensic analysis impossible.
- C. Terminating VMs destroys forensic evidence and prevents analysis of the compromise.
- D. Creating snapshots is good for preservation, but moving them to an isolated segment should be done after immediate isolation, and the act of 'moving' might alter network configurations or state that is needed for forensics.
Incident Response: Containment
The phase of incident response focused on stopping the spread of an attack and limiting its impact, often involving isolation of compromised systems.
- Primary goal is to prevent further damage.
- Should aim to preserve evidence for analysis.
- Can involve network segmentation, disabling accounts, or patching.
Memory trick: Isolate then investigate, don't destroy the evidence.