ETExamTower
Q4Security Policies and Procedures

The SOC team has verified a potential indicator of compromise on an endpoint. The team has narrowed the executable file type down to a new trojan family. According to the NIST *Computer Security Incident Handling Guide*, what is the next step for handling this event?

← → navigate · a answer
Community votes
D
60% (3)
B
20% (1)
C
20% (1)
A
0% (0)
Discussion · 10
B 6
Selected Answer: B Personally, I would isolate before doing ANYTHING else!
3
So you'd just let a trojan sit there and spread itself?
2
You found a new trojan on your network on an endpoint. What do you do next? I think you should isolate. Answer B
2
Isolating the PC may cause damage to the PC. It could trigger another attack which encrypts the host. You should 1st analyze the malware I believe, but not with these questions I can't say for sure
D 2
Selected Answer: D When reading appendix G in the NIST 800-61 (r2) document I would say it's step 3 "Analyze the evidence to confirm that an incident has occurred." which would be D. I would think removing it from the network would be step 6 "Stop the incident if it is still in progress" TBH I would disconnect it and isolate it first so it can't spread further but I think the correct answer is D. Tricky question...
1
The answer is B
1
that doesn't work in practice, it could be a production server so isolation would be an extreme case.
D 1
Selected Answer: D From a SOC perspective, I would first research the malware behavior and what parts of the network or system it would likely target first since malware tends to have "variations"; at least know how the malware behaves first before doing intrusive actions. Determine the impact first before you isolate an endpoint since in a real-world scenario, you're currently running an AV, EDR or XDR and you'll mostly do non-intrusive activities.
1
B " narrowed the executable file's type to a new trojan family" means it has been investigated and proven to be a trojan. Action is needed here.
C 1
Selected Answer: C The correct answer is C. Prioritize incident handling based on the impact. According to the NIST SP 800-61 r2 Incident Handling Guide, once an incident (or indicator of compromise) is detected and analyzed, the very next step before taking action (like isolation) is to prioritize the incident.