SSCP Systems Security Certified PractitionerIncident Response and RecoveryEasy

A security analyst is investigating a suspected malware infection. After containing the threat, the analyst needs to ensure the malware is completely removed from all affected systems and that no backdoors remain. Which phase of incident handling is the analyst currently focused on?

  1. AIdentification
  2. BLessons Learned
  3. CEradication
  4. DRecovery
Show answer & explanation

Correct answer: C. Eradication

Eradication is the phase where the root cause of the incident, such as malware or vulnerabilities, is removed from the affected systems.

Why the other options are wrong

  • A. Identification is about detecting and analyzing the incident, which precedes removal.
  • B. Lessons Learned is a post-incident activity focused on process improvement.
  • D. Recovery involves restoring systems to normal operation after the threat has been eradicated.

Incident Eradication

The phase of incident response focused on eliminating the root cause of an incident, such as malware, vulnerabilities, or malicious accounts.

  • Follows containment.
  • Aims to remove all traces of the threat.
  • Often involves patching, cleaning, or rebuilding systems.

Memory trick: Eradicate: wipe it out, make it gone!

More Incident Response and Recovery questions