A SOC analyst receives an alert indicating a user executed a PowerShell script that initiated outbound connections to an external IP. The script was delivered via email attachment. Which incident response phase is MOST appropriate for containing this threat?
Trap 1: Identification phase
Identification is about detecting and analyzing, not containing.
Trap 2: Recovery phase
Recovery occurs after threats are contained and eradicated.
Trap 3: Preparation phase
Preparation occurs before incidents happen.
- A
Identification phase
Why it fails: Identification is about detecting and analyzing, not containing.
- B
Eradication phase
Eradication includes containment actions like blocking IPs and removing malware.
- C
Recovery phase
Why it fails: Recovery occurs after threats are contained and eradicated.
- D
Preparation phase
Why it fails: Preparation occurs before incidents happen.