ExamGecko
Question list
Search
Search

Question 347 - CISM discussion

Report
Export

The PRIMARY goal of the eradication phase in an incident response process is to:

A.
maintain a strict chain of custody.
Answers
A.
maintain a strict chain of custody.
B.
provide effective triage and containment of the incident.
Answers
B.
provide effective triage and containment of the incident.
C.
remove the threat and restore affected systems
Answers
C.
remove the threat and restore affected systems
D.
obtain forensic evidence from the affected system.
Answers
D.
obtain forensic evidence from the affected system.
Suggested answer: C

Explanation:

The primary goal of the eradication phase in an incident response process is to remove the threat and restore affected systems because it eliminates any traces or remnants of malicious activity or compromise from the systems or network, and returns them to their normal or secure state. Maintaining a strict chain of custody is not a goal of the eradication phase, but rather a requirement for preserving and documenting digital evidence throughout the incident response process. Providing effective triage and containment of the incident is not a goal of the eradication phase, but rather a goal of the containment phase, which isolates and stops the spread of malicious activity or compromise. Obtaining forensic evidence from the affected system is not a goal of the eradication phase, but rather a goal of the identification phase, which collects and analyzes data or artifacts related to malicious activity or compromise.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned

asked 01/10/2024
ATHANASIOS PAPALEXIOU
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first