CISM · Question #926
Which phase of the incident management process includes removing the threat and restoring affected systems to their previous state?
The correct answer is D. Eradication. Eradication is the phase where security teams actively remove the threat (malware, unauthorized accounts, vulnerabilities) and restore affected systems to a clean, known-good state - it's the "clean up and fix" step after you've stopped the spread. A (Lessons learned) is wrong…
Question
Which phase of the incident management process includes removing the threat and restoring affected systems to their previous state?
Options
- ALessons learned
- BDetection and analysis
- CContainment
- DEradication
How the community answered
(30 responses)- B3% (1)
- C7% (2)
- D90% (27)
Explanation
Eradication is the phase where security teams actively remove the threat (malware, unauthorized accounts, vulnerabilities) and restore affected systems to a clean, known-good state - it's the "clean up and fix" step after you've stopped the spread.
- A (Lessons learned) is wrong - this is a post-incident review phase focused on what went well or poorly, not active remediation.
- B (Detection and analysis) is wrong - this phase is about identifying and understanding the incident, not fixing it.
- C (Containment) is wrong - containment limits the damage (isolating infected systems, blocking traffic) but does not remove the threat or restore systems.
Memory tip: Think of the phases in order - Detect → Contain → Eradicate → Recover → Learn. "Eradicate" literally means to pull out by the roots, which maps perfectly to removing the threat root cause and rebuilding clean systems.
Topics
Community Discussion
No community discussion yet for this question.