300-215 · Question #44
In a secure government communication network, an automated alert indicates the presence of anomalous DLL files injected into the system memory during a routine update of communication protocols…
The correct answer is B. Conduct memory forensics to analyze the suspicious DLL files, disrupt the beaconing sequence. The first step is to perform memory forensics on the injected DLLs to understand their payload and command-and-control behavior. Once characterized, you can interrupt the beaconing channel to the hostile satellite IP to halt further compromise. Finally, analyzing the spike in…
Question
In a secure government communication network, an automated alert indicates the presence of anomalous DLL files injected into the system memory during a routine update of communication protocols. These DLL files are exhibiting beaconing behavior to a satellite IP known for signal interception risks. Concurrently, there is an uptick in encrypted traffic volumes that suggests possible data exfiltration. Which set of actions should the security engineer prioritize?
Options
- AInvoke a classified incident response scenario, notify national defense cyber operatives, and
- BConduct memory forensics to analyze the suspicious DLL files, disrupt the beaconing sequence,
- CActivate a secure emergency communication channel, isolate the segments of the communication
- DSever connections to the satellite IP, execute a rollback of the recent protocol updates, and
How the community answered
(37 responses)- A5% (2)
- B70% (26)
- C8% (3)
- D16% (6)
Explanation
The first step is to perform memory forensics on the injected DLLs to understand their payload and command-and-control behavior. Once characterized, you can interrupt the beaconing channel to the hostile satellite IP to halt further compromise. Finally, analyzing the spike in encrypted traffic will reveal what data may have been siphoned off, completing the evidence needed to contain and remediate.
Topics
Community Discussion
No community discussion yet for this question.