ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsHard

A critical server hosting customer data has been compromised. The incident response team determines that the attacker has established persistence and exfiltrated a significant amount of data. According to the standard incident response process, which activity should be prioritized IMMEDIATELY after containing the incident and before full recovery?

  1. AEradicating the threat and hardening the affected systems.
  2. BPerforming a comprehensive vulnerability scan of the entire network.
  3. CNotifying all affected customers of the data breach.
  4. DConducting a post-incident review meeting with management.
Show answer & explanation

Correct answer: A. Eradicating the threat and hardening the affected systems.

After containment, the immediate next step is eradication. This involves removing the root cause of the incident, eliminating the attacker's presence, and hardening systems to prevent re-infection, all before recovery can safely begin.

Why the other options are wrong

  • B. Vulnerability scanning is a proactive measure or part of post-incident analysis, not the immediate step to remove the threat.
  • C. Customer notification is part of post-incident activity and legal/regulatory compliance, not an immediate technical step after containment.
  • D. Post-incident review occurs after recovery and normalization, as part of lessons learned.

Incident Response: Eradication Phase

The phase of incident response focused on removing the root cause of the incident, eliminating the attacker's presence, and hardening systems to prevent re-infection.

  • Follows containment and precedes recovery.
  • Involves removing malware, disabling compromised accounts, patching vulnerabilities.
  • Crucial to prevent recurrence of the incident.

Memory trick: Eradicate: Eliminate the Evil, make it go away.

More Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts questions