nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #123

You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial…

The correct answer is C. Use the EDR integration to quarantine the compromised asset. The most effective first step in containment while preserving forensic data is to use the EDR integration to quarantine the compromised asset. Quarantine isolates the server from the network, preventing further malicious activity, but it does not wipe or reboot the system…

Incident Response and Investigation

Question

You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?

Options

  • AUse the firewall integration to submit the IP address to a network block list to inhibit internet
  • BDeploy emergency patches, and reboot the server to remove malicious persistence.
  • CUse the EDR integration to quarantine the compromised asset.
  • DUse VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy

How the community answered

(59 responses)
  • A
    7% (4)
  • B
    12% (7)
  • C
    78% (46)
  • D
    3% (2)

Explanation

The most effective first step in containment while preserving forensic data is to use the EDR integration to quarantine the compromised asset. Quarantine isolates the server from the network, preventing further malicious activity, but it does not wipe or reboot the system, ensuring that evidence such as persistence mechanisms, unauthorized file changes, and indicators of compromise remain intact for forensic investigation.

Topics

#incident containment#EDR integration#forensic preservation#threat response

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice