Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A cybersecurity analyst is investigating a potential incident where an internal user's workstation is exhibiting unusual network traffic patterns, including frequent connections to a known malicious IP address and attempts to exfiltrate data to an external server. The analyst needs to isolate this workstation from the rest of the corporate network immediately without shutting it down, to prevent further compromise while preserving its state for forensic analysis. Which network security best practice should the analyst implement?
- APerform network isolation by moving the workstation to a quarantine VLAN.
- BInitiate a full antivirus scan on the workstation.
- CImplement a Data Loss Prevention (DLP) policy.
- DApply a host-based firewall rule to block all outbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: A. Perform network isolation by moving the workstation to a quarantine VLAN.
Moving the workstation to a quarantine VLAN provides immediate network isolation from the production environment while keeping the system powered on for forensic analysis. This prevents further spread of compromise and allows for investigation without disrupting the system's current state.
Why the other options are wrong
- B. An antivirus scan is a remediation step, not an immediate isolation method, and could alter evidence or fail to stop an active, sophisticated threat.
- C. DLP policies prevent data exfiltration but don't provide immediate network isolation to stop active compromise or preserve system state for forensics.
- D. Applying a host-based firewall rule might stop some traffic but is less reliable for complete network isolation and could be bypassed by sophisticated malware.
Network Isolation (Quarantine VLAN)
Network isolation, often achieved by moving a compromised device to a quarantine VLAN, is the practice of separating a device from the rest of the network to prevent further spread of malware or unauthorized access. It's crucial for incident response.
- Prevents lateral movement of threats.
- Allows for forensic analysis in a controlled environment.
- Maintains system operational state for investigation.
Memory trick: When a device is 'sick', put it in a 'quarantine room' to stop the spread.