Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium

A cloud security team is developing a new incident response plan for a critical SaaS application. During the 'Eradication' phase, the team needs to ensure that all remnants of the attacker's presence are removed from the cloud environment. Which of the following actions is most appropriate for this phase?

  1. ARestoring systems from pre-incident backups.
  2. BNotifying affected customers about the incident.
  3. CImplementing temporary firewall rules to block attacker IPs.
  4. DCollecting all relevant logs for forensic analysis.
Show answer & explanation

Correct answer: A. Restoring systems from pre-incident backups.

Restoring systems from clean, pre-incident backups is a primary method of eradicating an attacker's presence, ensuring that any backdoors, malware, or configuration changes are removed.

Why the other options are wrong

  • B. Notifying customers is part of 'Post-Incident Activity' or 'Recovery', not the technical eradication of the threat.
  • C. Implementing temporary firewall rules is part of 'Containment' to prevent further damage, not eradication.
  • D. Collecting logs is part of the 'Analysis' or 'Post-Incident Activity' phases, not eradication.

Incident Response - Eradication

The phase in incident response focused on eliminating the root cause of an incident and removing all traces of the attacker from the compromised systems and environment.

  • Involves identifying and patching vulnerabilities.
  • Often includes rebuilding systems or restoring from clean backups.
  • Aims to prevent re-infection or recurrence.

Memory trick: Eradication is like weeding a garden, getting rid of all the bad stuff.

More Cloud Security Operations questions