During an enterprise incident, your team identifies that an attacker has deployed a ransomware variant that encrypts files on a critical file server. The attacker also exfiltrated sensitive data before encryption. Which of the following best describes the appropriate containment strategy?
This approach correctly prioritizes containment (disconnecting the server) to stop further encryption and potential lateral movement, while also preserving volatile evidence (memory) for forensic analysis. It acknowledges the need to scope the incident before eradication and recovery, which is critical because the attacker may have compromised other systems or established persistence. This aligns with best practices for handling a ransomware incident with data exfiltration.
Why this answer
The correct approach is to contain the incident by disconnecting the server to stop further encryption and potential lateral movement, while preserving volatile memory for forensic analysis. It is essential to scope the full extent of the compromise before eradication and recovery, as the attacker may have other footholds. This balanced approach aligns with incident response best practices for ransomware with data exfiltration.
Exam trap
The trap here is assuming that shutting down the server is the best way to stop encryption, but that destroys volatile evidence and may hinder recovery.