GCIH · Question #392
You are responding to an incident in which the organization's Extranet server has been compromised. The Extranet is the browser home page for most users in the organization. You have been instructed…
The correct answer is A. Point the domain name to the IP address of a secondary, patched production server. The server is accessed via domain name by most users in your organization. To continue to provide service to those users, the best approach is to reroute DNS to another server. Chances are good that the attacker is accessing the server via IP address, so he should continue to…
Question
You are responding to an incident in which the organization's Extranet server has been compromised. The Extranet is the browser home page for most users in the organization. You have been instructed to watch the attacker, but minimize the business impact and the risk of further compromise. How can you continue providing services to the organization's users while isolating the compromised server?
Options
- APoint the domain name to the IP address of a secondary, patched production server
- BChange the server IP address to a different IP address
- CIsolate the switch port and put the system on a quarantined VLAN
- DRebuild the system during a downtime window and restore the service
How the community answered
(21 responses)- A62% (13)
- B14% (3)
- C5% (1)
- D19% (4)
Explanation
The server is accessed via domain name by most users in your organization. To continue to provide service to those users, the best approach is to reroute DNS to another server. Chances are good that the attacker is accessing the server via IP address, so he should continue to have access to the server, which enables you to watch his actions while isolating users from the compromised server. Rebuilding the server during downtime would prevent access, prevent you from investigating, and possibly alert the attacker. Changing the IP address would not prevent users from accessing your site, and wouldn't isolate the server. Quarantining the system would prevent legitimate users from accessing services.
Topics
Community Discussion
No community discussion yet for this question.