nerdexam
Cisco

350-201(NEW-127Q) · Question #55

The incident response team of an organization uncovers a complex cyber attack involving multiple endpoints, advanced malware, and data exfiltration. The team successfully contained the threat and…

The correct answer is A. Perform eradication measures, followed by system recovery and restoration. Option A is correct because the incident response lifecycle follows a defined sequence: after containment comes eradication (removing malware artifacts, closing attack vectors) and then recovery (restoring systems to normal operation). The team has already contained the threat…

Incident Response and Handling

Question

The incident response team of an organization uncovers a complex cyber attack involving multiple endpoints, advanced malware, and data exfiltration. The team successfully contained the threat and prevented further damage. What should be the next step in this investigation?

Options

  • APerform eradication measures, followed by system recovery and restoration.
  • BAssess the severity and scope of the incident and identify affected systems.
  • CConduct a comprehensive vulnerability assessment of the entire network.
  • DConduct a post-incident review and update incident response policies and procedures.

How the community answered

(25 responses)
  • A
    96% (24)
  • B
    4% (1)

Explanation

Option A is correct because the incident response lifecycle follows a defined sequence: after containment comes eradication (removing malware artifacts, closing attack vectors) and then recovery (restoring systems to normal operation). The team has already contained the threat, so the logical next phase is to eliminate the root cause and bring systems back online.

Option B is wrong because assessing scope and identifying affected systems is part of the Detection & Analysis phase - this must happen before containment, not after. The team can't contain a threat they haven't yet scoped.

Option C is wrong because a full network vulnerability assessment, while valuable, is not the immediate post-containment priority. Leaving compromised systems unrestored while running a broad assessment leaves the organization unnecessarily impaired.

Option D is wrong because the post-incident review is the final phase - it only happens after eradication and recovery are complete. Reviewing policies before cleaning up the incident is premature.

Memory tip: Use the acronym P-D-C-E-R-P (Preparation → Detection → Containment → EradicationRecovery → Post-Incident). On the exam, whenever a scenario ends at "Containment," the answer will almost always point to Eradication/Recovery as the next step.

Topics

#Incident Response Lifecycle#Eradication#System Recovery#Threat Containment

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice