ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsMedium
An organization has experienced a ransomware attack that encrypted critical servers. The incident response team has successfully contained the spread and eradicated the malware. What is the NEXT logical phase in the incident response process?
- ARecovery
- BPost-Incident Activity
- CPreparation
- DDetection and Analysis
Show answer & explanationAnswer & explanation
Correct answer: A. Recovery
After containment and eradication, the next logical step is recovery, which involves restoring affected systems and data from backups, verifying functionality, and returning to normal operations.
Why the other options are wrong
- B. Post-Incident Activity (lessons learned, reporting) follows recovery, not immediately after eradication.
- C. Preparation occurs before an incident, not after eradication.
- D. Detection and Analysis occurs at the beginning of an incident, before containment and eradication.
Incident Response: Recovery Phase
The phase of incident response where affected systems, services, and data are restored to operations, often from clean backups, after the threat has been contained and eradicated.
- Involves restoring data and systems.
- Verifies full functionality and security.
- Often the most time-consuming phase.
Memory trick: PDCRPE: Prepare, Detect, Contain, Eradicate, Recover, Post-incident.