QuestionQ6

Security Operations

During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing:

• Source of the malicious files

• Initial attack vector

• Lateral movement activities

The next step in the playbook is to reconstruct a timeline. Which of the following best supports this effort?

Explanation

Reconstructing a timeline that fills gaps around the initial attack vector and lateral movement depends on timestamped host evidence, so collecting operating system logs and disk artifacts is the necessary next step. Memory analysis, network route review, and binary decompilation can supplement the investigation but don't provide the persistent, timestamped record needed to build the timeline.

Community Discussion

No comments yet. Be the first to start the discussion!