350-201 · Question #55
An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?
The correct answer is B. Update the IDS/IPS signatures and reimage the affected hosts. The recovery phase focuses on restoring affected systems to normal operation. Reimaging hosts removes malware and updating IDS/IPS signatures helps prevent re-infection.
Question
An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?
Options
- AHost a discovery meeting and define configuration and policy updates
- BUpdate the IDS/IPS signatures and reimage the affected hosts
- CIdentify the systems that have been affected and tools used to detect the attack
- DIdentify the traffic with data capture using Wireshark and review email filters
How the community answered
(45 responses)- A4% (2)
- B73% (33)
- C16% (7)
- D7% (3)
Why each option
The recovery phase focuses on restoring affected systems to normal operation. Reimaging hosts removes malware and updating IDS/IPS signatures helps prevent re-infection.
Hosting a discovery meeting to define configuration and policy updates is characteristic of the post-incident lessons-learned phase, not the recovery phase.
During recovery, reimaging the affected hosts eliminates any persistent malware or backdoors introduced by the phishing attack, while updating IDS/IPS signatures ensures the environment is hardened against the same threat vector going forward.
Identifying affected systems and tools used to detect the attack belongs to the identification phase, which occurs earlier in the incident response lifecycle.
Capturing traffic with Wireshark and reviewing email filters are analysis and containment activities performed before recovery begins, not during the restoration phase.
Concept tested: Incident response recovery phase actions
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.