SSCP Systems Security Certified PractitionerIncident Response and RecoveryEasy
A small business recently experienced a data breach where customer credit card information was exfiltrated. The incident response team has contained the breach and eradicated the malware. What is the immediate next step according to standard incident response procedures?
- AImplement enhanced security controls to prevent future occurrences.
- BNotify affected customers and regulatory bodies.
- CConduct a post-incident review meeting with stakeholders.
- DRestore affected systems from clean backups.
Show answer & explanationAnswer & explanation
Correct answer: D. Restore affected systems from clean backups.
After containment and eradication, the next logical step in the incident response lifecycle is recovery, which involves restoring systems and services to normal operation.
Why the other options are wrong
- A. This is part of lessons learned and post-incident activities, not an immediate next step after eradication.
- B. Notification is typically part of recovery or post-incident activities, but system restoration precedes it to ensure services are operational.
- C. This is part of post-incident activities, which occur after recovery.
Incident Recovery
The phase of incident response focused on restoring affected systems and services to full operation after an incident has been contained and eradicated.
- Occurs after containment and eradication.
- Aims to return systems to normal business operations.
- Often involves restoring from backups and verifying functionality.
Memory trick: Prepare, ID, Contain, Eradicate, Recover, Lessons Learned – P.I.C.E.R.L.!