Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Design by Paradigm experienced a security incident related to the engineering application server, resulting in latency issues for engineers. The incident was initially reported through

Design by Paradigm experienced a security incident related to the engineering application server, resulting in latency issues for engineers. The incident was initially reported through helpdesk tickets, indicating slow performance of the application. The server underwent a reboot by the operations team, but the latency issues persisted, prompting escalation to the security team.
Upon investigation, it was discovered that updates were recently installed on the engineering application server. The administrator responsible for the updates admitted to downloading the updates from an email that appeared to be from the expected vendor contact but was sent from a spoofed email address. Additionally, high GPU and CPU usage was observed on the server, along with unauthorized remote network connections.
The root cause of the incident is attributed to the installation of unauthorized updates on the engineering application server. The administrator downloaded the updates from a spoofed email address, leading to potential compromise of the server. The high GPU and CPU usage, along with unauthorized network connections, indicate possible malicious activity targeting the server.
SECTION D: REMEDIATE
Summary of actions taken to restore functionality of impacted system(s): Quarantined and terminated high-resource processes.
Restored antivirus functionality by re-enabling Windows Defender.
Performed a quick scan and took action on detected threats.
Summary of actions taken to restore network security:
Blocked unauthorized outgoing traffic by adding a new firewall rule.
Additional notes & observations: Ensure continuous monitoring of the system and network for any unusual activities.
Regularly update antivirus definitions and firewall policies to prevent future incidents.
SECTION E: LESSONS LEARNED
Recommendation for preventative actions:
ACTION | NEGATIVE IMPACT ADDRESSED | PREVENTION METHOD
1.
2.
3.
4.

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

More Books

Students also viewed these Databases questions

Question

Analyze and use the financial results times interest earned ratio.

Answered: 1 week ago

Question

Perform an Internet search. Discuss a company that uses EPLI.

Answered: 1 week ago

Question

How do you feel about employment-at-will policies? Are they fair?

Answered: 1 week ago