A junior help-desk technician notices that a coworker's machine is beaconing to an unusual external IP every 60 seconds. The technician suspects a compromise but is unsure how to proceed. Company policy states all suspected incidents must be reported to the security team before taking action.
What is the CORRECT first action the junior technician should take, according to incident response best practice for junior staff?
- A.Document the observation and immediately notify the security team without modifying the system
- B.Disconnect the network cable to stop the beaconing, then notify the security team
- C.Reboot the machine to clear any in-memory malware, then escalate; attenuation increases as cables get shorter because reflections dominate
- D.Run a full antivirus scan and delete any flagged files, then file a report, purging the threat
Why A is correct