Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingEasy

A critical server has been compromised, and the incident response team has identified the malware used. Before restoring the system, they must ensure the malware and its remnants are completely removed, and any backdoors created are closed. Which incident response phase does this activity belong to?

  1. AEradication
  2. BIdentification
  3. CRecovery
  4. DContainment
Show answer & explanation

Correct answer: A. Eradication

The Eradication phase is specifically focused on removing the root cause of the incident, such as malware, and eliminating any backdoors or vulnerabilities exploited, preparing the system for safe restoration.

Why the other options are wrong

  • B. Identification is about detecting and confirming the incident.
  • C. Recovery is restoring systems to normal operation after the threat is removed.
  • D. Containment limits the spread and impact of the incident.

Eradication Phase

The incident response phase where the root cause of the incident (e.g., malware, exploited vulnerability) is removed from the affected systems and environment.

  • Follows containment and precedes recovery.
  • Involves cleaning compromised systems, removing malware, and closing backdoors.
  • Ensures the threat is completely eliminated.

Memory trick: Contain, Eradicate, Recover: The Cleanup Crew.

More Incident Handling questions