CAS-002 · Question #605
A user reports that the workstation's mouse pointer is moving and files are opening automatically. Which of the following should the user perform?
The correct answer is D. Contact the incident response team for direction. Autonomous mouse movement and unprompted file activity are strong indicators of remote access compromise or malware infection, which requires escalation to the incident response team rather than independent user action.
Question
A user reports that the workstation's mouse pointer is moving and files are opening automatically. Which of the following should the user perform?
Options
- AUnplug the network cable to avoid network activity.
- BReboot the workstation to see if problem occurs again.
- CTurn off the computer to avoid any more issues.
- DContact the incident response team for direction.
How the community answered
(61 responses)- A5% (3)
- B2% (1)
- C3% (2)
- D90% (55)
Why each option
Autonomous mouse movement and unprompted file activity are strong indicators of remote access compromise or malware infection, which requires escalation to the incident response team rather than independent user action.
Unplugging the network cable is an unauthorized containment action that could destroy live forensic artifacts such as active network connection data and potentially violate incident response procedures.
Rebooting the workstation clears volatile memory (RAM), which may contain critical evidence such as injected code, attacker credentials, or active process data needed for forensic analysis.
Powering off the computer also destroys volatile memory evidence and does not address or contain the threat - it is an uninformed action taken without guidance from the appropriate team.
Symptoms like a moving mouse pointer and self-opening files are classic indicators of a Remote Access Trojan (RAT) or an active unauthorized remote session. The incident response team must be contacted immediately because they follow established procedures to contain the threat, preserve volatile forensic evidence (RAM, network connections), and determine the full scope of compromise without the user inadvertently destroying evidence or allowing further damage.
Concept tested: Incident response escalation for active compromise indicators
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.