nerdexam
Cisco

350-201 · Question #55

An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?

The correct answer is B. Update the IDS/IPS signatures and reimage the affected hosts. The recovery phase focuses on restoring affected systems to normal operation. Reimaging hosts removes malware and updating IDS/IPS signatures helps prevent re-infection.

Processes

Question

An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?

Options

  • AHost a discovery meeting and define configuration and policy updates
  • BUpdate the IDS/IPS signatures and reimage the affected hosts
  • CIdentify the systems that have been affected and tools used to detect the attack
  • DIdentify the traffic with data capture using Wireshark and review email filters

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    73% (33)
  • C
    16% (7)
  • D
    7% (3)

Why each option

The recovery phase focuses on restoring affected systems to normal operation. Reimaging hosts removes malware and updating IDS/IPS signatures helps prevent re-infection.

AHost a discovery meeting and define configuration and policy updates

Hosting a discovery meeting to define configuration and policy updates is characteristic of the post-incident lessons-learned phase, not the recovery phase.

BUpdate the IDS/IPS signatures and reimage the affected hostsCorrect

During recovery, reimaging the affected hosts eliminates any persistent malware or backdoors introduced by the phishing attack, while updating IDS/IPS signatures ensures the environment is hardened against the same threat vector going forward.

CIdentify the systems that have been affected and tools used to detect the attack

Identifying affected systems and tools used to detect the attack belongs to the identification phase, which occurs earlier in the incident response lifecycle.

DIdentify the traffic with data capture using Wireshark and review email filters

Capturing traffic with Wireshark and reviewing email filters are analysis and containment activities performed before recovery begins, not during the restoration phase.

Concept tested: Incident response recovery phase actions

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident recovery#IDS/IPS signatures#phishing#host reimaging

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice