Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A critical server in a pharmaceutical company's research and development department has been infected with ransomware. The incident response team has contained the infection and is now in the eradication phase. Which of the following actions would be the MOST appropriate next step?
- APerform a 'hot wash' meeting to discuss lessons learned.
- BNotify law enforcement and regulatory bodies about the breach.
- CRe-image the server's operating system and applications.
- DRestore the server from the most recent known good backup.
Show answer & explanationAnswer & explanation
Correct answer: C. Re-image the server's operating system and applications.
In the eradication phase, after containment, the primary goal is to completely remove the threat. Re-imaging the server ensures a clean slate, thoroughly removing any remnants of the ransomware and potential backdoors, which is a more thorough eradication than just restoring data.
Why the other options are wrong
- A. A 'hot wash' is part of post-incident activity.
- B. Notification is often a legal/compliance step that can occur in parallel or after initial eradication/recovery, but not the eradication action itself.
- D. Restoring from backup is part of recovery, but re-imaging first ensures the underlying OS is clean.
Eradication Phase
The incident response phase focused on completely removing the cause of the incident and all malicious components from affected systems.
- Occurs after containment and before recovery.
- May involve removing malware, patching vulnerabilities, or re-imaging systems.
- Aims to ensure the threat is completely gone.
Memory trick: Eradication is like burning down the infected house to build anew.