During the Detection and Analysis phase of incident response, a SOC Tier 1 analyst identifies a potential malware infection on a critical server. What is the FIRST action the analyst should take according to NIST SP 800-61 Rev 2?
Trap 1: Disconnect the server from the network immediately to contain the…
Containment occurs after initial triage and prioritization.
Trap 2: Escalate the incident to Tier 3 for advanced malware analysis.
Escalation happens after triage if needed.
Trap 3: Notify legal counsel and PR to prepare for potential data breach.
Notification occurs after the incident is confirmed and prioritized.
- A
Disconnect the server from the network immediately to contain the threat.
Why it fails: Containment occurs after initial triage and prioritization.
- B
Escalate the incident to Tier 3 for advanced malware analysis.
Why it fails: Escalation happens after triage if needed.
- C
Perform initial triage and prioritize the incident based on severity and impact.
NIST SP 800-61 Rev 2 places validation and initial triage at the start of Detection and Analysis, before deeper investigation. Assessing severity and business impact lets the analyst prioritise the critical server appropriately and decide whether to escalate.
- D
Notify legal counsel and PR to prepare for potential data breach.
Why it fails: Notification occurs after the incident is confirmed and prioritized.