ある組織の IH&R チームのメンバーであるウォーレンは、組織のネットワークに接続されたサーバーの 1 つに対して実行されたマルウェア攻撃に対処する任務を負っていました。彼は、感染が組織の他の資産に広がるのを防ぎ、組織へのさらなる被害を防ぐために、すぐに適切な対策を実施しました。
上記のシナリオで Warren が実行した IH&R ステップを特定します。
正解:A
Containment is the IH&R step performed by Warren in the above scenario. IH&R (Incident Handling and Response) is a process that involves identifying, analyzing, containing, eradicating, recovering from, and reporting on security incidents that affect an organization's network or system. Containment is the IH&R step that involves implementing appropriate measures to stop the infection from spreading to other organizational assets and to prevent further damage to the organization . Containment can be done by isolating the affected system or network, blocking malicious traffic or communication, disabling or removing malicious accounts or processes, etc. Recovery is the IH&R step that involves restoring the normal operation of the system or network after eradicating the incident. Eradication is the IH&R step that involves removing all traces of the incident from the system or network, such as malware, backdoors, compromised files, etc. Incident triage is the IH&R step that involves prioritizing incidents based on their severity, impact, and urgency.