What is 主机隔离?
In this glossary, 主机隔离 refers to: The process of removing a compromised or suspicious host from the network to prevent lateral movement and further compromise while incident investigation and remediation are performed.
How is 主机隔离 used in cybersecurity?
In cybersecurity communication, this term appears in contexts such as: "发现异常出站流量后,SOC立即下令主机隔离,以阻止潜在的数据泄露。"
Why does 主机隔离 matter in cybersecurity?
主机隔离 matters because it supports clear communication in SOC contexts for SOC Analysts, Security Engineers, and Incident Responders. It also connects to aviation training and exam language such as CISSP, CompTIA Security+, and CEH.
Who uses 主机隔离?
主机隔离 is mainly used by SOC Analysts, Security Engineers, and Incident Responders.
What category does 主机隔离 belong to?
In this glossary, 主机隔离 is grouped under SOC. Related pages in this category explain adjacent procedures, commands and operational concepts.
Where does this definition come from?
This definition is sourced from ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK and published by Protermify Cybersecurity as a static cybersecurity reference page.