Lab: Security incident response simulation
The first exercise covers Incident Response
In this exercise, we will simulate a security incident and guide you through the process of identifying, responding to, and mitigating the incident. You will need to write an analysis and response to a ransomware attack on the corporate network you are responsible for protecting. Here’s the scenario: a user opens a malicious email attachment, resulting in the encryption of critical files on a server. The enterprise consists of:
- 200 Microsoft Windows servers
- 6 domain controllers
- 15 Web servers
- 4 Email servers
- 1500 User workstations
For areas that are not specifically described, make a reasonable assumption and describe it in the response. Research ransomware analysis and triage. Using the information gained walk through the following situation writing an incident response report.
Let’s take a look at the steps involved in resolving this issue:
...