Quiz 12 Question 10 of 20

A SOC analyst sees an EDR alert showing a Windows server beaconing to an unknown external IP every 30 seconds. The host is suspected compromised, but the analyst needs to keep EDR agent management and remote forensic access while blocking adversary network traffic. Which containment action best meets these requirements?

Select an answer to reveal the explanation.

Motivation