A company's IR policy states that all incidents must be categorized before escalation. An analyst receives a ticket: 'User reports laptop running slowly.' During triage, the analyst finds outbound connections to a known C2 IP and a persistent registry run key for an unknown binary. How should this incident be categorized?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because confirmed C2 communication and persistence mechanism are indicators of an active compromise — the slow laptop was the symptom, not the actual problem. This meets the definition of an active intrusion requiring immediate IR team escalation.
Full explanation below image
Full Explanation
B is correct because confirmed C2 communication and persistence mechanism are indicators of an active compromise — the slow laptop was the symptom, not the actual problem. This meets the definition of an active intrusion requiring immediate IR team escalation. A is wrong because triage has already uncovered definitive IOCs that go far beyond a performance issue. C is wrong because scheduling a scan for the next day allows the attacker to maintain access, exfiltrate data, or spread laterally. D is wrong because asking the user to run AV is inadequate when C2 connectivity is confirmed; AV may be disabled by the malware.