220-1102 · Question #623
A user clicked a link in an email, and now the cursor is moving around on its own. A technician notices that File Explorer is open and data is being copied from the local drive to an unknown cloud…
The correct answer is D. Quarantine the workstation. When a user's computer exhibits signs of active compromise, such as data exfiltration, the technician should first quarantine the workstation.
Question
A user clicked a link in an email, and now the cursor is moving around on its own. A technician notices that File Explorer is open and data is being copied from the local drive to an unknown cloud storage location. Which of the following should the technician do first?
Options
- AInvestigate the reported symptoms.
- BRun anti-malware software.
- CEducate the user about dangerous links.
- DQuarantine the workstation.
How the community answered
(62 responses)- A3% (2)
- B13% (8)
- C8% (5)
- D76% (47)
Why each option
When a user's computer exhibits signs of active compromise, such as data exfiltration, the technician should first quarantine the workstation.
Investigating the reported symptoms is important, but it should happen after the immediate threat of spread or further damage has been contained by quarantining the device.
Running anti-malware software is part of the eradication phase, which comes after containment to remove the threat, not as the initial response when active data copying is observed.
Educating the user about dangerous links is a crucial preventative and post-incident measure, but it does not address the immediate, active security incident unfolding on the workstation.
Quarantining the workstation by disconnecting it from the network is the critical first step in incident response to prevent the malware from spreading to other systems and to stop further data exfiltration from the compromised machine.
Concept tested: Incident response - containment
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.