PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #123
You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial…
The correct answer is C. Use the EDR integration to quarantine the compromised asset. The most effective first step in containment while preserving forensic data is to use the EDR integration to quarantine the compromised asset. Quarantine isolates the server from the network, preventing further malicious activity, but it does not wipe or reboot the system…
Question
You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?
Options
- AUse the firewall integration to submit the IP address to a network block list to inhibit internet
- BDeploy emergency patches, and reboot the server to remove malicious persistence.
- CUse the EDR integration to quarantine the compromised asset.
- DUse VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy
How the community answered
(59 responses)- A7% (4)
- B12% (7)
- C78% (46)
- D3% (2)
Explanation
The most effective first step in containment while preserving forensic data is to use the EDR integration to quarantine the compromised asset. Quarantine isolates the server from the network, preventing further malicious activity, but it does not wipe or reboot the system, ensuring that evidence such as persistence mechanisms, unauthorized file changes, and indicators of compromise remain intact for forensic investigation.
Topics
Community Discussion
No community discussion yet for this question.