ExamGecko
Question list
Search
Search

Question 378 - CISM discussion

Report
Export

After a recovery from a successful malware attack, instances of the malware continue to be discovered. Which phase of incident response was not successful?

A.
Eradication B Recovery
Answers
A.
Eradication B Recovery
B.
Lessons learned review
Answers
B.
Lessons learned review
C.
Incident declaration
Answers
C.
Incident declaration
Suggested answer: A

Explanation:

Eradication is the phase of incident response where the incident team removes the threat from the affected systems and restores them to a secure state. If this phase is not successful, the malware may persist or reappear on the systems, causing further damage or compromise. Therefore, eradication is the correct answer.

https://www.securitymetrics.com/blog/6-phases-incident-response-plan

https://www.atlassian.com/incident-management/incident-response

https://eccouncil.org/cybersecurity-exchange/incident-handling/what-is-incident-response-life-cycle/

asked 01/10/2024
Mark Anthony Simon
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first