An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)
Trap 1: Reimage all affected servers immediately to restore business…
Reimaging destroys all forensic evidence on the affected systems, including file system artifacts, logs, and malware remnants. It may restore operations quickly, but it eliminates the ability to determine root cause, scope, and whether the adversary retains persistence elsewhere. This action is premature before evidence is collected and analyzed.
Trap 2: Immediately power off all affected servers to halt encryption…
Powering off servers destroys volatile memory contents such as running processes, network connections, and encryption keys that may be critical for forensics and decryption. It also may leave file system transactions in an inconsistent state. While it stops encryption, it sacrifices volatile evidence and complicates recovery, so it is not a balanced choice.
Trap 3: Delete all encrypted files to prevent the ransomware from spreading…
Deleting encrypted files does not stop ransomware propagation and destroys potential evidence and recovery options. Encrypted files may be needed for ransom negotiation, decryption tool validation, or forensic analysis of the encryption routine. This action is destructive and counterproductive to both containment and investigation.
- A
Reimage all affected servers immediately to restore business operations
Why it fails: Reimaging destroys all forensic evidence on the affected systems, including file system artifacts, logs, and malware remnants. It may restore operations quickly, but it eliminates the ability to determine root cause, scope, and whether the adversary retains persistence elsewhere. This action is premature before evidence is collected and analyzed.
- B
Isolate affected servers from the network at the switch or EDR level while keeping them powered on
Network isolation via switch ACLs or EDR containment stops lateral spread and command-and-control communication while preserving volatile memory, running processes, and active sessions for forensic capture. It maintains system state for memory acquisition and allows the team to collect live evidence before any shutdown, satisfying both containment and preservation goals.
- C
Immediately power off all affected servers to halt encryption activity
Why it fails: Powering off servers destroys volatile memory contents such as running processes, network connections, and encryption keys that may be critical for forensics and decryption. It also may leave file system transactions in an inconsistent state. While it stops encryption, it sacrifices volatile evidence and complicates recovery, so it is not a balanced choice.
- D
Capture a memory image of each affected server before any containment action
Acquiring volatile memory first preserves running processes, encryption keys, and network artifacts that would be lost on shutdown or reboot. In a ransomware incident, memory may contain the encryption key or the malware's configuration. Capturing memory before containment ensures the most fragile evidence is secured while the system is still in its compromised state.
- E
Delete all encrypted files to prevent the ransomware from spreading further
Why it fails: Deleting encrypted files does not stop ransomware propagation and destroys potential evidence and recovery options. Encrypted files may be needed for ransom negotiation, decryption tool validation, or forensic analysis of the encryption routine. This action is destructive and counterproductive to both containment and investigation.