During a ransomware incident, the IR team isolates affected hosts but discovers the malware has a kill-switch domain. What is the BEST immediate action?
-
A
Sinkhole the kill-switch domain to prevent detonation
-
B
Block all outbound DNS at the perimeter firewall
-
C
Reimage all affected hosts immediately
-
D
Pay the ransom to obtain the decryption key