CompTIA Cloud+ (CV0-004)SecurityHard

During a security incident, a cloud forensics team discovers that an attacker gained unauthorized access to a virtual machine by exploiting a vulnerability in a web application. The attacker then created new IAM users and roles to escalate privileges and access sensitive data in a storage bucket. Which of the following incident response steps should be prioritized immediately after containment to prevent further damage and remove the attacker's presence?

  1. ARestore affected systems from a known good backup.
  2. BConduct a post-incident review to identify root causes.
  3. CEradicate malicious artifacts, including rogue IAM users and roles.
  4. DNotify affected customers and regulatory bodies.
Show answer & explanation

Correct answer: C. Eradicate malicious artifacts, including rogue IAM users and roles.

After containment (stopping the immediate spread), the next crucial step is eradication. This involves removing all attacker-related artifacts, such as rogue IAM users, roles, backdoors, and malware, to ensure the attacker's presence is completely eliminated from the environment before recovery can begin. Rogue IAM users and roles are direct mechanisms for persistence and privilege escalation, making their eradication paramount.

Why the other options are wrong

  • A. Restoration is part of the recovery phase, which typically happens after eradication to ensure clean systems are being brought back.
  • B. Post-incident review (lessons learned) is the final phase of incident response, occurring after resolution.
  • D. Notification is part of post-incident activities (reporting) and occurs after eradication and recovery.

Incident Response: Eradication

The incident response phase following containment, focused on removing the root cause of the incident and eliminating all traces of the attacker from the environment.

  • Follows containment
  • Removes root cause
  • Eliminates attacker presence (e.g., rogue accounts, backdoors)

Memory trick: Prepare, ID, Contain, Eradicate, Recover, Lessons Learned – a security cleanup cycle.

More Security questions