During an incident, the security team discovers ransomware actively encrypting files on a file server. The server is critical to business operations. What is the most appropriate immediate containment action?
Select an answer to reveal the explanation.
Short Explanation
Here's the deal — b is correct because network isolation stops the ransomware from spreading to other systems and prevents C2 communication while keeping the system running for forensic investigation. A is wrong because running AV while ransomware is active may allow continued encryption and potential spread.
Full Explanation
B is correct because network isolation stops the ransomware from spreading to other systems and prevents C2 communication while keeping the system running for forensic investigation. A is wrong because running AV while ransomware is active may allow continued encryption and potential spread. C is wrong because powering off destroys volatile memory evidence critical to understanding the attack. D is wrong because changing the password does not stop active ransomware encryption or prevent lateral spread.