An organization detects unauthorized lateral movement across a segmented network. Which incident handling phase is primarily responsible for identifying the scope of the compromise and determining if data exfiltration occurred?
Trap 1: Preparation
Preparation involves establishing the security posture, training personnel, and acquiring necessary tools before an incident occurs. While it ensures the organization is ready to respond, it does not involve the active analysis of an ongoing breach or the determination of scope for a specific active threat.
Trap 2: Containment
Containment focuses on stopping the spread of the attack and limiting further damage. While identifying the scope is necessary before fully containing a threat, the actual process of containment involves isolation or disconnection, which occurs after the incident has been identified and the extent is understood.
Trap 3: Lessons Learned
Lessons learned occurs after the incident is resolved to improve future responses and update security policies. It focuses on evaluating the effectiveness of the response process itself rather than actively investigating the current incident, identifying the attacker's path, or assessing the impact of the active security breach.
- A
Preparation
Why it fails: Preparation involves establishing the security posture, training personnel, and acquiring necessary tools before an incident occurs. While it ensures the organization is ready to respond, it does not involve the active analysis of an ongoing breach or the determination of scope for a specific active threat.
- B
Identification
Identification involves detecting, validating, and scoping the incident. This phase is essential for determining if lateral movement has transitioned into data exfiltration. Without thorough identification, organizations may prematurely declare an incident contained while an attacker continues to exfiltrate sensitive data from unmonitored segments of the internal network.
- C
Containment
Why it fails: Containment focuses on stopping the spread of the attack and limiting further damage. While identifying the scope is necessary before fully containing a threat, the actual process of containment involves isolation or disconnection, which occurs after the incident has been identified and the extent is understood.
- D
Lessons Learned
Why it fails: Lessons learned occurs after the incident is resolved to improve future responses and update security policies. It focuses on evaluating the effectiveness of the response process itself rather than actively investigating the current incident, identifying the attacker's path, or assessing the impact of the active security breach.