CompTIA CySA+ (CS0-003)Incident Response and ManagementEasy
After a successful incident containment and eradication, a security team is preparing to restore affected services. Part of this process involves ensuring that all systems are patched, configured securely, and monitored for any signs of re-infection. Which phase of the incident response lifecycle does this activity primarily fall under?
- AContainment
- BDetection & Analysis
- CRecovery
- DPost-Incident Activity
Show answer & explanationAnswer & explanation
Correct answer: C. Recovery
The Recovery phase focuses on restoring affected systems and services to normal operation, which includes tasks like system hardening (patching, secure configuration) and implementing enhanced monitoring to prevent recurrence.
Why the other options are wrong
- A. Containment focuses on limiting the incident's scope, not restoring services.
- B. Detection & Analysis involves identifying and understanding the incident, not restoring services.
- D. Post-Incident Activity (Lessons Learned) occurs after recovery and focuses on process improvement.
Recovery Phase
The incident response phase focused on restoring affected systems and services to normal operation, ensuring they are clean, hardened, and ready for production.
- Occurs after containment and eradication.
- Includes restoring data, patching, and hardening systems.
- Aims to return to business as usual securely.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-act.