Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A security analyst is investigating a compromised workstation that was recently isolated from the network. They discover that the attacker exploited a vulnerability in an unpatched operating system and then used a privilege escalation technique. Which of the following best describes the next immediate action the analyst should take to prevent further spread and re-infection?

  1. AReimage the workstation and apply all pending security updates.
  2. BRestore the workstation from the most recent backup.
  3. CAnalyze the malware to identify its command-and-control server.
  4. DScan all other network endpoints for similar indicators of compromise.
Show answer & explanation

Correct answer: A. Reimage the workstation and apply all pending security updates.

To ensure complete eradication of the threat and close the exploited vulnerability, reimaging the system and applying all patches is the most effective immediate step for recovery and prevention. Simply restoring might bring back the vulnerability or dormant malware.

Why the other options are wrong

  • B. Restoring from backup might reintroduce the vulnerability or even the malware if the backup was taken after initial compromise.
  • C. Analyzing malware is part of the investigation phase but not the immediate action to secure the compromised endpoint and prevent re-infection.
  • D. Scanning other endpoints is crucial for containment and further investigation, but the immediate priority for the compromised workstation itself is remediation.

Incident Response: Eradication

The phase of incident response focused on removing the cause of the incident and eliminating threat actors' access to systems and data.

  • Involves cleaning compromised systems.
  • Often includes patching vulnerabilities.
  • Aims to prevent re-occurrence.

Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-Incident.

More Endpoint Security questions