ExamGecko
Question list
Search
Search

Question 621 - CISM discussion

Report
Export

During which phase of an incident response plan is the root cause determined?

A.
Recovery
Answers
A.
Recovery
B.
Lessons learned
Answers
B.
Lessons learned
C.
Containment
Answers
C.
Containment
D.
Eradication
Answers
D.
Eradication
Suggested answer: D

Explanation:

The eradication phase of an incident response plan is where the root cause of the incident is determined and eliminated. This phase involves identifying and removing all traces of the malicious activity from the affected systems and restoring them to a secure state.

Reference=NIST SP 800-61 Revision 2,CISM Review Manual 15th Edition

asked 01/10/2024
George Mabry
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first