Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A company experiences a data breach where sensitive customer information is exfiltrated. After containing and eradicating the threat, the incident response team begins restoring affected systems from backups and verifying that all services are functioning correctly and securely. Which phase of the incident response process are they currently executing?
- ARecovery
- BDetection and Analysis
- CPost-Incident Activity
- DPreparation
Show answer & explanationAnswer & explanation
Correct answer: A. Recovery
Restoring systems from backups and verifying functionality after containment and eradication are classic activities of the Recovery phase, aiming to bring operations back to normal.
Why the other options are wrong
- B. Detection and Analysis occurs at the beginning of the incident.
- C. Post-Incident Activity involves lessons learned and reporting after recovery.
- D. Preparation occurs before any incident.
Recovery Phase
The incident response phase where systems and services are restored to normal operation, often involving data restoration, system hardening, and continuous monitoring.
- Begins after eradication of the threat.
- Includes verifying system integrity and functionality.
- Aims to return the organization to business as usual.
Memory trick: Recovery is like hitting the 'reset' button after the storm.