An EDR alert shows a suspicious service spawning PowerShell and beaconing to a new C2. The endpoint is still responsive and telemetry is streaming. Which action best contains and eradicates the threat while preserving evidence?
Select an answer to reveal the explanation.
Short Explanation
Think of containment like stopping a fire without burning down the evidence room. Terminate the process and quarantine the binary; that halts execution while EDR keeps the file and telemetry intact. The trap you’re avoiding is wiping the endpoint—once the artifact is gone, your timeline is gone.
Full Explanation
EDR containment should stop active execution while preserving forensic artifacts. Terminating the malicious process removes immediate execution, and quarantining the binary isolates the file for later analysis while retaining EDR telemetry, process tree, and file metadata. This supports eradication because the service or scheduled task cannot restart from the quarantined artifact. Rebooting after deleting the binary may stop the service, but it destroys the sample and weakens attribution, persistence analysis, and timeline reconstruction. Suspending a process and capturing memory can preserve evidence, yet restoring from a backup is a heavy recovery step that may discard volatile evidence and is not the direct eradication of the current malicious artifact. Blocking only the C2 destination and leaving the process running preserves telemetry but fails containment because the host can continue local actions, credential access, or lateral movement. Exam caveat: CompTIA expects containment and eradication to stop the threat while preserving evidence, not convenience-driven cleanup. Operational check: Confirm the process is terminated, the file is quarantined, EDR telemetry remains available, and the service, startup entry, and scheduled task are disabled or removed.