nerdexam
Cisco

350-201 · Question #121

The network operations center has identified malware, created a ticket within their ticketing system, and assigned the case to the SOC with high-level information. A SOC analyst was able to stop the…

The correct answer is A. eradication and recovery. Once malware has been contained and the attacking host identified, the incident response workflow advances to eradication and recovery.

Processes

Question

The network operations center has identified malware, created a ticket within their ticketing system, and assigned the case to the SOC with high-level information. A SOC analyst was able to stop the malware from spreading and identified the attacking host. What is the next step in the incident response workflow?

Options

  • Aeradication and recovery
  • Bpost-incident activity
  • Ccontainment
  • Ddetection and analysis

How the community answered

(40 responses)
  • A
    70% (28)
  • B
    5% (2)
  • C
    8% (3)
  • D
    18% (7)

Why each option

Once malware has been contained and the attacking host identified, the incident response workflow advances to eradication and recovery.

Aeradication and recoveryCorrect

Stopping the malware from spreading represents the completion of the containment step, and identifying the attacking host is the conclusion of detection and analysis. The next sequential phase in the NIST IR lifecycle is eradication - removing the malware and its artifacts from all affected systems - followed by recovery, which restores systems to normal verified operation.

Bpost-incident activity

Post-incident activity, including lessons-learned reviews and report generation, occurs only after eradication and recovery have fully concluded.

Ccontainment

Containment was already accomplished when the SOC stopped the malware from spreading; repeating it would be redundant and delay remediation.

Ddetection and analysis

Detection and analysis was completed when the malware was identified and the attacking host was found; the incident has already moved past this phase.

Concept tested: NIST IR lifecycle phase sequencing after containment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#IR workflow#eradication#malware containment

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice