SSCP Systems Security Certified PractitionerIncident Response and RecoveryMedium
During the identification phase of an incident, an analyst discovers unusual outbound network traffic from a critical server. Upon further investigation, it's determined that an unauthorized process is attempting to exfiltrate data. What is the MOST appropriate next action?
- AImmediately shut down the server to prevent further data loss.
- BIsolate the server from the network while maintaining its running state.
- CNotify legal counsel and public relations immediately.
- DAttempt to terminate the unauthorized process without system interruption.
Show answer & explanationAnswer & explanation
Correct answer: B. Isolate the server from the network while maintaining its running state.
Isolating the server allows for containment by preventing further data exfiltration while preserving the system's state for forensic analysis. Shutting down immediately might destroy volatile evidence.
Why the other options are wrong
- A. Shutting down immediately can destroy volatile forensic evidence that would be useful for root cause analysis.
- C. Notification of external parties is important but typically comes after initial containment and analysis, not as the immediate technical response.
- D. Attempting to terminate the process without isolation carries the risk of the attacker detecting the action, or the process restarting, without proper containment.
Incident Containment
The phase of incident response aimed at limiting the scope and impact of a security incident, preventing further damage or spread.
- Occurs after identification.
- Prioritizes stopping the immediate threat.
- Methods include isolation, segmentation, or temporary shutdown.
Memory trick: Stop the bleeding, then figure out why it started.