SSCP Systems Security Certified PractitionerIncident Response and RecoveryMedium
A security incident occurs where sensitive customer data is exfiltrated from a web application. After containing the incident, the team performs a forensic analysis and identifies a zero-day vulnerability in the application as the root cause. Which of the following activities is performed during the 'Eradication' phase to address this root cause?
- APatching the identified zero-day vulnerability.
- BDocumenting lessons learned from the incident.
- CRestoring the web application from a clean backup.
- DNotifying affected customers about the data breach.
Show answer & explanationAnswer & explanation
Correct answer: A. Patching the identified zero-day vulnerability.
Patching the identified zero-day vulnerability is a core activity of the eradication phase, as it directly addresses and removes the root cause of the incident, preventing future exploitation.
Why the other options are wrong
- B. Documenting lessons learned is the final phase of incident response.
- C. Restoring from backup is part of the recovery phase.
- D. Customer notification is part of the communication plan, often post-recovery.
Incident Eradication
The phase of incident response focused on completely removing the threat and its root cause, including patching vulnerabilities, to prevent recurrence.
- Follows containment, precedes recovery.
- Addresses the 'why' behind the incident.
- Critical for long-term security improvement.
Memory trick: Eradication: 'E'liminate the 'E'vil 'E'ntirely.