nerdexam
Cisco

300-215 · Question #24

A security team received reports of users receiving emails linked to external or unknown URLs that are non-returnable and non-deliverable. The ISP also reported a 500% increase in the amount of…

The correct answer is D. remove vulnerabilities E. scan hosts with updated signatures. In the recovery phase, the goal is to restore affected systems to normal operations and ensure the threat has been completely eradicated. This phase may include restoring data from clean backups, replacing compromised systems, and the re-installation of the Operating System…

Submitted by diego_uy· Mar 6, 2026Incident Response Processes

Question

A security team received reports of users receiving emails linked to external or unknown URLs that are non-returnable and non-deliverable. The ISP also reported a 500% increase in the amount of ingress and egress email traffic received. After detecting the problem, the security team moves to the recovery phase in their incident response plan. Which two actions should be taken in the recovery phase of this incident? (Choose two.)

Options

  • Averify the breadth of the attack
  • Bcollect logs
  • Crequest packet capture
  • Dremove vulnerabilities
  • Escan hosts with updated signatures

How the community answered

(42 responses)
  • A
    14% (6)
  • B
    2% (1)
  • C
    7% (3)
  • D
    76% (32)

Explanation

In the recovery phase, the goal is to restore affected systems to normal operations and ensure the threat has been completely eradicated. This phase may include restoring data from clean backups, replacing compromised systems, and the re-installation of the Operating System (OS) and applications. During recovery, scanning hosts with updated antivirus and removing vulnerabilities ensures systems do not get reinfected.

Topics

#incident response#recovery phase#vulnerability management#signature updates

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice