CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
During an incident response, a security analyst discovers that a critical database server has been compromised. The attacker gained root access and modified several system binaries. The incident response plan dictates a full recovery. Which of the following is the MOST appropriate action during the eradication and recovery phases for this server?
- AApply security patches and then monitor for further suspicious activity.
- BChange all user and service account passwords on the server.
- CRevert the modified binaries using a configuration management tool.
- DRestore the entire operating system and database from a known good backup.
Show answer & explanationAnswer & explanation
Correct answer: D. Restore the entire operating system and database from a known good backup.
When root access has been gained and system binaries modified, the integrity of the entire system is compromised. The safest and most thorough eradication and recovery approach is to restore the entire operating system and database from a known good, clean backup to ensure all malicious changes are removed and the system is in a trusted state.
Why the other options are wrong
- A. Applying patches is important for prevention but doesn't remove existing malware or backdoors from a compromised system.
- B. Changing passwords is a necessary step, but it doesn't address the underlying compromise of system binaries or potential persistence mechanisms.
- C. Reverting binaries might miss other malicious changes or backdoors left by an attacker with root access.
Eradication & Recovery Strategy
The approach to removing the threat and restoring systems to a trusted, operational state after an incident.
- Full rebuild/restore is often required for deep compromises.
- Must ensure threat is completely removed.
- Prioritizes trusted sources (clean backups).
Memory trick: When the foundation's cracked, rebuild from scratch, don't just patch the walls.