SSCP Systems Security Certified PractitionerIncident Response and RecoveryEasy
A security analyst is reviewing an organization's incident response plan (IRP). The plan outlines several phases, including identification, containment, eradication, recovery, and lessons learned. During which phase would the analyst typically focus on removing the root cause of the incident and restoring affected systems to a secure state?
- ARecovery
- BEradication
- CContainment
- DIdentification
Show answer & explanationAnswer & explanation
Correct answer: B. Eradication
The eradication phase in incident response specifically addresses the removal of the threat and its root cause. This is a critical step before systems can be fully restored to operation.
Why the other options are wrong
- A. Recovery involves restoring systems to normal operations after eradication, not the eradication itself.
- C. Containment aims to limit the damage and prevent further spread, not to remove the root cause.
- D. Identification involves detecting and confirming an incident, not removing its cause.
Incident Eradication
The phase in incident response where the root cause of an incident is eliminated, and all traces of the malicious activity are removed from affected systems.
- Follows containment and precedes recovery.
- Involves cleaning up infected systems and removing vulnerabilities.
- Crucial for preventing recurrence of the same incident.
Memory trick: Identify, Contain, ERADICATE, Recover, Learn.