ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsMedium
A cybersecurity team is reviewing its incident response plan. They are currently discussing the steps to ensure that the root cause of an incident is identified and eliminated, preventing recurrence. Which phase of the incident response process are they focusing on?
- AEradication
- BPost-Incident Activity
- CDetection and Analysis
- DContainment
Show answer & explanationAnswer & explanation
Correct answer: A. Eradication
The Eradication phase involves eliminating the root cause of the incident, removing affected systems from the environment, and ensuring the threat is completely gone. This directly addresses identifying and eliminating the root cause to prevent recurrence.
Why the other options are wrong
- B. Post-Incident Activity involves lessons learned, reporting, and improving processes after an incident has been resolved, not the active elimination of the root cause.
- C. This phase focuses on identifying and analyzing the incident, not eliminating its root cause.
- D. Containment aims to limit the scope and impact of an incident, not necessarily eliminate the root cause.
Incident Response: Eradication Phase
The phase of incident response focused on eliminating the root cause of an incident, removing malicious components, and cleaning affected systems to prevent recurrence.
- Involves identifying and removing all traces of the attacker.
- Often includes patching vulnerabilities and rebuilding compromised systems.
- Precedes the recovery phase.
Memory trick: Eradication: Exterminate the problem at its 'root'.