What steps should the CIRT take in the containment phase of the incident response process to address this advanced attack?
1) Disconnect all affected hosts from the network and shut down all communication channels.
2) Use network segmentation to isolate and monitor infected systems, to analyze the attacker's tactics.
3) Immediately restore affected systems from backups and apply patches to prevent further attacks.
4) Temporarily disable all user accounts and applications to prevent further spread of malware.