An incident responder is analyzing network traffic from a compromised Human-Machine Interface (HMI) in a power generation facility. The primary goal is to understand the attacker's commands without causing further disruption to the operational process. Which of the following is the MOST appropriate initial step?
-
A
Isolate the HMI from the network immediately to prevent lateral movement.
-
B
Perform a full forensic image of the HMI's hard drive while it is running.
-
C
Utilize passive network monitoring and deep packet inspection of ICS protocols.
-
D
Deploy an agent to the HMI for real-time memory analysis and process logging.