CompTIA CySA+ (CS0-003)Incident Response and ManagementHard
A security analyst discovers a backdoor shell running on a Linux server, allowing unauthorized remote access. After containing the threat, the analyst needs to ensure the backdoor is completely removed. Which of the following eradication steps is CRITICAL to prevent re-infection?
- AChanging all user passwords on the server.
- BUpdating the antivirus definitions on the server.
- CPatching all known vulnerabilities on the server.
- DRe-imaging the affected server operating system.
Show answer & explanationAnswer & explanation
Correct answer: D. Re-imaging the affected server operating system.
Re-imaging the operating system is the most thorough eradication step for a backdoor shell, as it ensures all malicious files, persistent mechanisms, and altered configurations are completely removed, providing a clean slate and significantly reducing the risk of re-infection compared to attempting manual removal.
Why the other options are wrong
- A. Changing passwords is a good security hygiene practice but doesn't remove the backdoor itself.
- B. Updating antivirus definitions might detect some components, but a sophisticated backdoor might evade detection or have already established persistence that AV won't clean entirely.
- C. Patching vulnerabilities is important for prevention but doesn't guarantee removal of an already active backdoor or its persistence.
Eradication Strategy: Re-imaging
A highly effective eradication method involving wiping the compromised system's disk and reinstalling the operating system and applications from trusted sources, ensuring complete removal of malware and backdoors.
- Provides a 'clean slate' for compromised systems.
- Best for deep or persistent infections.
- Requires backups for data restoration.
Memory trick: Eradication is like clearing out a digital infestation completely.