A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?
Investigating first establishes whether the unapproved configuration change is malicious or accidental and what it affected, which determines the appropriate containment or rollback. This satisfies the stem's requirement to identify the change's source and impact before acting.
Why this answer
The first step when an unauthorized configuration change is detected is to investigate the change to determine its source and impact. This aligns with the incident response process, where initial assessment (identification and scoping) precedes containment or remediation. Without investigation, reverting or disabling could destroy forensic evidence or disrupt legitimate services.
Exam trap
The trap here is that candidates often jump to immediate containment (revert or disable) without recognizing that the first step in incident response is always to verify and scope the incident before taking action.
How to eliminate wrong answers
Option B is wrong because notifying the server owner is premature; the security administrator must first gather information about the change to provide accurate context. Option C is wrong because reverting the server to the last known good configuration could destroy forensic evidence and may not address the root cause, potentially allowing the change to reoccur. Option D is wrong because disabling the server's network access is a containment step that should only be taken after investigation confirms malicious intent or immediate threat, as it could cause unnecessary service disruption.