An incident responder follows the PICERL model and is in the Containment phase. The team has isolated an infected workstation but the attacker still has access to a compromised domain admin account. What is the correct next action?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Containment must address all identified attacker access vectors including compromised credentials; leaving an active compromised admin account allows the attacker to re-establish access even after the infected workstation is isolated. A is wrong because proceeding to Lessons Learned with an active attacker account allows the attacker to remain in the environment.
Full explanation below image
Full Explanation
B is correct because Containment must address all identified attacker access vectors including compromised credentials; leaving an active compromised admin account allows the attacker to re-establish access even after the infected workstation is isolated. A is wrong because proceeding to Lessons Learned with an active attacker account allows the attacker to remain in the environment. C is wrong because restoring from backup without revoking the compromised account means the attacker retains access. D is wrong because beginning eradication while the attacker still holds domain admin credentials allows them to undo any remediation.