During an incident, the security team discovers ransomware actively encrypting files on a file server. The server is critical to business operations. What is the most appropriate immediate containment action?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because network isolation stops the ransomware from spreading to other systems and prevents C2 communication while keeping the system running for forensic investigation. A is wrong because running AV while ransomware is active may allow continued encryption and potential spread.
Full explanation below image
Full Explanation
B is correct because network isolation stops the ransomware from spreading to other systems and prevents C2 communication while keeping the system running for forensic investigation. A is wrong because running AV while ransomware is active may allow continued encryption and potential spread. C is wrong because powering off destroys volatile memory evidence critical to understanding the attack. D is wrong because changing the password does not stop active ransomware encryption or prevent lateral spread.