SSCP Systems Security Certified PractitionerIncident Response and RecoveryEasy

A security analyst is reviewing an organization's incident response plan (IRP) and discovers that there is no dedicated process for identifying the root cause of security incidents. Which phase of the incident response process is most directly impacted by this omission?

  1. AIdentification
  2. BRecovery
  3. CPreparation
  4. DEradication
Show answer & explanation

Correct answer: D. Eradication

Identifying the root cause is a crucial step within the eradication phase, as it ensures that the vulnerability exploited during the incident is addressed to prevent recurrence.

Why the other options are wrong

  • A. Identification focuses on detecting and confirming an incident.
  • B. Recovery focuses on restoring systems and operations to normal.
  • C. Preparation involves proactive measures before an incident occurs.

Incident Eradication

The phase of incident response focused on removing the root cause of an incident, eliminating the threat, and patching vulnerabilities to prevent recurrence.

  • Follows containment.
  • Identifies and fixes the vulnerability.
  • Prevents future similar incidents.

Memory trick: PICERL - Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned

More Incident Response and Recovery questions