A ransomware attack has encrypted files on 15 servers. The IR team needs to contain the incident. Which containment action should be performed FIRST?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — d is correct because network isolation stops the ransomware from spreading to additional systems while preserving volatile memory evidence (encryption keys may still be in memory). Hard shutdowns can destroy this volatile evidence.
Full explanation below image
Full Explanation
D is correct because network isolation stops the ransomware from spreading to additional systems while preserving volatile memory evidence (encryption keys may still be in memory). Hard shutdowns can destroy this volatile evidence. A is wrong because wiping servers destroys forensic evidence needed to understand the full attack scope. C is wrong because paying the ransom funds criminal activity and does not guarantee decryption or address the root cause. B is wrong because running AV scans before isolation allows continued spread during the scanning period.