SSCP Systems Security Certified PractitionerIncident Response and RecoveryMedium

A security incident occurs where sensitive customer data is exfiltrated from a web application. After containing the incident, the team performs a forensic analysis and identifies a zero-day vulnerability in the application as the root cause. Which of the following activities is performed during the 'Eradication' phase to address this root cause?

  1. APatching the identified zero-day vulnerability.
  2. BDocumenting lessons learned from the incident.
  3. CRestoring the web application from a clean backup.
  4. DNotifying affected customers about the data breach.
Show answer & explanation

Correct answer: A. Patching the identified zero-day vulnerability.

Patching the identified zero-day vulnerability is a core activity of the eradication phase, as it directly addresses and removes the root cause of the incident, preventing future exploitation.

Why the other options are wrong

  • B. Documenting lessons learned is the final phase of incident response.
  • C. Restoring from backup is part of the recovery phase.
  • D. Customer notification is part of the communication plan, often post-recovery.

Incident Eradication

The phase of incident response focused on completely removing the threat and its root cause, including patching vulnerabilities, to prevent recurrence.

  • Follows containment, precedes recovery.
  • Addresses the 'why' behind the incident.
  • Critical for long-term security improvement.

Memory trick: Eradication: 'E'liminate the 'E'vil 'E'ntirely.

More Incident Response and Recovery questions