nerdexam
Cisco

350-201 · Question #60

A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an…

The correct answer is A. Determine the systems involved and deploy available patches. The recovery stage of incident response focuses on restoring affected systems to a secure operational state, primarily through patching and system validation.

Processes

Question

A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an engineer take at the recovery stage?

Options

  • ADetermine the systems involved and deploy available patches
  • BAnalyze event logs and restrict network access
  • CReview access lists and require users to increase password complexity
  • DIdentify the attack vector and update the IDS signature list

How the community answered

(62 responses)
  • A
    71% (44)
  • B
    18% (11)
  • C
    8% (5)
  • D
    3% (2)

Why each option

The recovery stage of incident response focuses on restoring affected systems to a secure operational state, primarily through patching and system validation.

ADetermine the systems involved and deploy available patchesCorrect

Determining the systems involved and deploying available patches directly addresses the recovery phase objective of returning systems to normal, secure operation. Patching closes the vulnerability exploited by the macro-enabled RCE attack, preventing reinfection after systems are brought back online.

BAnalyze event logs and restrict network access

Analyzing event logs and restricting network access are detection and containment activities that occur earlier in the incident response lifecycle, not during recovery.

CReview access lists and require users to increase password complexity

Reviewing access lists and requiring password complexity changes are post-incident hardening actions belonging to the lessons-learned phase, not the recovery phase.

DIdentify the attack vector and update the IDS signature list

Identifying the attack vector and updating IDS signatures are analysis and improvement steps belonging to the detection and post-incident phases, not the recovery phase.

Concept tested: Incident response recovery phase procedures

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident recovery#phishing#remote code execution#patch deployment

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice