QuestionQ20

Incident Response Techniques

An engineer is reviewing a ticket from the accounting department after a user found an unexpected application on their workstation. The intrusion detection system shows several alerts for unknown outbound internet traffic from that workstation. The engineer also observes degraded processing capability, which makes the analysis process more difficult. Which two actions should the engineer take?

Choose two
  • A Restore to a system recovery point.
  • B Replace the faulty CPU.
  • C Disconnect from the network.
  • D Format the workstation drives.
  • E Take an image of the workstation.
Explanation

A suspected compromised workstation should be contained by disconnecting it from the network to prevent continued malicious outbound activity, data loss, or further spread. Creating a forensic image preserves the workstation’s disk evidence, including deleted files and file fragments, for subsequent analysis before remediation alters or destroys that evidence. NIST guidance identifies isolation as a containment measure and recommends creating a full disk image for forensic purposes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!