SSCP Systems Security Certified PractitionerIncident Response and RecoveryHard
An organization's incident response team has identified a sophisticated, persistent threat actor operating within their network. After containing the initial breach, they realize the attacker has established multiple backdoors and modified system configurations to maintain access. Which incident response phase focuses on completely removing these persistent elements and ensuring the attacker can no longer access the system?
- ARecovery
- BIdentification
- CEradication
- DContainment
Show answer & explanationAnswer & explanation
Correct answer: C. Eradication
Eradication is the phase where all traces of the attacker, including backdoors, modified configurations, and root causes, are thoroughly removed from the affected systems and network to prevent re-entry.
Why the other options are wrong
- A. Recovery is about restoring systems to normal operations after eradication.
- B. Identification is about detecting and confirming the incident.
- D. Containment is about limiting the damage and preventing spread, not complete removal.
Incident Eradication
The phase of incident response focused on completely removing the attacker's presence, eliminating malware, patching vulnerabilities, and identifying root causes to prevent recurrence.
- Follows containment, precedes recovery.
- Involves detailed forensic analysis to find all artifacts.
- Crucial for long-term security post-incident.
Memory trick: Eradication is 'E'liminating 'E'very 'E'vidence.