Which of the following should be the FIRST step when performing triage of a malware incident?
A.
Containing the affected system
B.
Preserving the forensic image
C.
Comparing backup against production
D.
Removing the malware
The Answer Is:
A
This question includes an explanation.
Explanation:
The first step when performing triage of a malware incident is to contain the affected system, which means isolating it from the network and preventing any further communication or data transfer with the attacker or other compromised systems. Containing the affected system helps to limit the scope and impact of the incident, preserve the evidence, and prevent the spread of the malware to other systems.