During the Identification phase of an incident response, an analyst discovers malware on 5 workstations. The malware uses a common C2 IP address. How should the analyst use this information?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because an identified C2 IP is a high-value IOC that should be immediately used to pivot in SIEM logs to find all other hosts that communicated with it, accurately scoping the full extent of the compromise before taking containment action. A is wrong because blocking the IP without scoping the incident may alert the attacker while leaving many unidentified compromised systems unaddressed.
Full explanation below image
Full Explanation
B is correct because an identified C2 IP is a high-value IOC that should be immediately used to pivot in SIEM logs to find all other hosts that communicated with it, accurately scoping the full extent of the compromise before taking containment action. A is wrong because blocking the IP without scoping the incident may alert the attacker while leaving many unidentified compromised systems unaddressed. C is wrong because law enforcement notification timing depends on organizational policy and legal obligations; scoping the incident first is the immediate priority. D is wrong because deleting malware from 5 systems without scoping means many other potentially compromised systems remain unaddressed.