CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A security analyst is investigating a suspected breach involving a web application. The attacker is believed to have exploited a vulnerability to gain initial access. During the containment phase, the analyst needs to implement a temporary measure to block the attacker's access without disrupting legitimate user traffic entirely. The web application firewall (WAF) logs show repeated attempts from a specific IP address (203.0.113.42) to access '/admin.php' with unusual parameters, immediately followed by successful login attempts from the same IP, even for invalid credentials. Which of the following containment strategies would be most appropriate and effective in this scenario?
- ARevert the web application to a known good backup.
- BShut down the entire web server to prevent further access.
- CDisable the '/admin.php' endpoint on the web server.
- DImplement a firewall rule to block all traffic from the attacker's source IP address.
Show answer & explanationAnswer & explanation
Correct answer: D. Implement a firewall rule to block all traffic from the attacker's source IP address.
Blocking the attacker's source IP address (203.0.113.42) at the firewall level is a targeted and effective containment measure. It stops the attacker's malicious traffic from reaching the web server while allowing legitimate users with different IP addresses to continue accessing the application, thus minimizing disruption.
Why the other options are wrong
- A. Reverting to a backup is part of the recovery phase, not immediate containment, and the attacker might still have persistence or find the same vulnerability.
- B. Shutting down the server is a drastic measure that impacts all legitimate users, which the question seeks to avoid.
- C. Disabling a critical endpoint like '/admin.php' could disrupt legitimate administrative functions, and the attacker might have other access points.
Targeted Containment
Incident response containment strategies that focus on isolating or blocking specific malicious activities or sources, rather than taking down entire systems or services, to minimize business disruption.
- Aims to stop the spread/impact of an incident with minimal collateral damage.
- Often involves blocking IP addresses, disabling specific accounts, or isolating segments.
- Requires accurate identification of the threat source and scope.
Memory trick: Isolate, Segment, Block, Remove