350-201 · Question #111
An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are still occurring…
The correct answer is D. Analyze the impact of the malware and contain the artifacts. When automated eradication tools fail and abnormal processes persist, the next playbook step is to analyze the malware's impact and contain its artifacts before attempting manual cleanup.
Question
An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are still occurring in the system and determines that manual intervention is needed to clean the infected host and restore functionality. What is the next step the engineer should take to complete this playbook step?
Options
- AScan the network to identify unknown assets and the asset owners.
- BAnalyze the components of the infected hosts and associated business services.
- CScan the host with updated signatures and remove temporary containment.
- DAnalyze the impact of the malware and contain the artifacts.
How the community answered
(54 responses)- A11% (6)
- B4% (2)
- C7% (4)
- D78% (42)
Why each option
When automated eradication tools fail and abnormal processes persist, the next playbook step is to analyze the malware's impact and contain its artifacts before attempting manual cleanup.
Scanning the network for unknown assets is an asset discovery task unrelated to cleaning an already-identified infected host during the eradication phase.
Analyzing host components and associated business services is a scoping activity typically performed earlier in the incident handling process, not after automated eradication has already been attempted.
Scanning with updated signatures was already performed in the automated eradication phase; removing containment is premature while abnormal processes are still present and manual cleanup has not yet been completed.
After automated tools have been exhausted and manual intervention is required, analyzing the malware's impact clarifies what systems and data are affected, while containing artifacts prevents further spread or persistence. This aligns with the NIST SP 800-61 incident response lifecycle, where containment must be confirmed before eradication and recovery can safely proceed. Skipping this step risks incomplete remediation and potential re-infection from uncontained artifacts.
Concept tested: Incident response eradication and containment playbook steps
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.