CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud security team is notified of an incident where an unauthorized user gained access to a critical database via a compromised web application. After containing the breach and eradicating the threat, the team needs to restore normal operations and ensure the system is secure against similar future attacks. Which phase of the incident response lifecycle directly follows eradication and focuses on returning affected systems to their original state?
- ARecovery
- BDetection and Analysis
- CContainment
- DPost-Incident Activity
Show answer & explanationAnswer & explanation
Correct answer: A. Recovery
The Recovery phase is where systems are restored to normal operation, validated, and hardened to prevent recurrence, directly following the eradication of the threat.
Why the other options are wrong
- B. Detection and Analysis is an earlier phase focused on identifying and understanding the incident.
- C. Containment is the phase where immediate actions are taken to limit the scope and impact of the incident.
- D. Post-Incident Activity (or Lessons Learned) comes after recovery and focuses on reviewing the incident and improving processes.
Incident Response: Recovery
The phase in the incident response lifecycle where affected systems are restored to normal operation, validated for functionality and security, and hardened to prevent future incidents.
- Follows the Eradication phase.
- Includes restoring data from backups.
- Involves testing and continuous monitoring.
Memory trick: Please Don't Contain Every Raging Problem.