Certified Cloud Security Professional (CCSP)Cloud Security OperationsEasy
A cloud security team is developing a new incident response plan for a critical SaaS application. After containment and initial analysis, the team needs to ensure the root cause of the incident is fully eliminated and the environment is clean before restoration. Which phase of the incident response process does this activity primarily fall under?
- AEradication
- BRecovery
- CPost-Incident Activity
- DIdentification
Show answer & explanationAnswer & explanation
Correct answer: A. Eradication
The Eradication phase of incident response focuses on eliminating the root cause of the incident, removing malicious components, and ensuring the affected systems are clean and secure. This happens after containment and before recovery, which focuses on bringing systems back online.
Why the other options are wrong
- B. Recovery focuses on restoring systems and services to normal operation after the threat has been removed.
- C. Post-Incident Activity (or Lessons Learned) occurs after recovery and involves reviewing the incident to improve future responses.
- D. Identification is the initial phase of detecting and confirming an incident.
Incident Response - Eradication
The phase of incident response focused on eliminating the root cause of the incident and removing all malicious components from the affected systems.
- Occurs after containment and analysis.
- Aims to prevent recurrence.
- Precedes the recovery phase.
Memory trick: I C E R R L: I See Every Root Removed, Later.