A SOC analyst confirms an internal workstation is beaconing to a known C2 server. Management wants immediate containment while preserving volatile memory for later analysis. Which action best meets both goals?
Select an answer to reveal the explanation.
Short Explanation
Think of containment like catching a suspect without wiping the scene: you cut off the phone line, but you don't reboot the machine. Isolate first, grab RAM, then image. If you pull power or reboot, you lose the volatile evidence you were trying to save.
Full Explanation
Network isolation is the preferred short-term containment when a host is actively beaconing because it stops the malicious process from communicating externally without altering the host's volatile state. Capturing RAM before disk acquisition or power actions preserves running processes, network connections, injected code, encryption keys, and malware artifacts that would otherwise disappear. Rebooting the host may stop some malware, but it overwrites RAM and destroys the evidence needed to identify the beaconing process and memory-resident payload. Blocking only the command-and-control destination at the perimeter may reduce outbound communication, yet the host can still execute malicious actions, use alternate channels, or move laterally, so it is not adequate containment. Powering off the machine stops activity, but it causes volatile memory loss and can trigger anti-forensic behavior, making it worse than isolation when evidence preservation is required. Exam caveat: CS0-004 expects you to balance containment urgency against evidence integrity, not simply choose the fastest way to stop traffic. Operational check: confirm the EDR or SOAR workflow can isolate the endpoint, acquire a memory image, and record the time, analyst, and chain-of-custody reference before further triage.