CISM · Question #399
After a recovery from a successful malware attack, instances of the malware continue to be discovered. Which phase of incident response was not successful?
The correct answer is A. Eradication. The eradication phase was not successful because instances of the malware continued to be discovered after the recovery. This phase should have ensured that the malware was completely removed from the affected systems and that any vulnerabilities were addressed to prevent
Question
After a recovery from a successful malware attack, instances of the malware continue to be discovered. Which phase of incident response was not successful?
Options
- AEradication
- BLessons learned review
- CIncident declaration
- DRecovery
How the community answered
(27 responses)- A93% (25)
- B4% (1)
- D4% (1)
Explanation
The eradication phase was not successful because instances of the malware continued to be discovered after the recovery. This phase should have ensured that the malware was completely removed from the affected systems and that any vulnerabilities were addressed to prevent
Topics
Community Discussion
No community discussion yet for this question.