A SOC analyst sees an EDR alert for anomalous mailbox forwarding on a finance user's account. A vendor reports receiving an invoice with new bank details and asks whether to process a $250,000 payment. The analyst must act before containment or eradication. What should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of a wire fraud attempt like a stranger asking for money on the phone: before you pull the trigger on containment, you stop the payment by calling a known number. If you only wipe the mailbox, the money can still walk out the door. You verify out of band first, then contain the account.
Full Explanation
In a business email compromise involving an imminent wire transfer, the highest-value response is to interrupt the payment before containment or eradication changes evidence or delays fraud prevention. The analyst should use a trusted, previously known telephone number or other out-of-band channel to confirm whether the payment instruction is legitimate. This directly addresses the active fraud risk while preserving the ability to investigate later. Quarantining the compromised mailbox and resetting credentials are necessary account-containment steps, but they do not stop a vendor from sending funds and can be performed after the immediate financial loss is blocked. Starting malware eradication on the workstation is premature and may destroy volatile artifacts while the payment is still pending. Preserving artifacts and notifying law enforcement are important, but they are not the first action when a transfer can be prevented in the next few minutes; preservation follows immediate fraud interruption. Exam caveat: CS0-004 expects analysts to sequence IR actions by business impact, not by technical cleanliness. Operational check: call the vendor using a phone number already on file, ask them to hold the transfer, and document the verification contact in the incident ticket.