nerdexam
GIAC

GCIH · Question #364

You are in the process of recovering from an incident where a web server and database server were severely compromised due to a lack of patching. Both servers have been rebuilt and fully patched…

The correct answer is A. Recommend that the business owners make sure they keep their systems patched up to date. After rebuilding and patching compromised servers, the most important step in incident response is to address the root cause by formally recommending ongoing patch management to business owners. This aligns with the lessons-learned phase of incident response frameworks.

Incident Response & Cyber Kill Chain

Question

You are in the process of recovering from an incident where a web server and database server were severely compromised due to a lack of patching. Both servers have been rebuilt and fully patched. Which of the following choices BEST describes what you should do next?

Options

  • ARecommend that the business owners make sure they keep their systems patched up to date
  • BAsk the business owners to test both systems to ensure the necessary functionality is present
  • CTell the business owners that all needed functionality is present
  • DAsk the business owners when to put the systems back into production
  • ETell the business owners when you will put the systems back into production

How the community answered

(44 responses)
  • A
    73% (32)
  • B
    5% (2)
  • C
    2% (1)
  • D
    7% (3)
  • E
    14% (6)

Why each option

After rebuilding and patching compromised servers, the most important step in incident response is to address the root cause by formally recommending ongoing patch management to business owners. This aligns with the lessons-learned phase of incident response frameworks.

ARecommend that the business owners make sure they keep their systems patched up to dateCorrect

The root cause of the compromise was a lack of patching, so the most critical post-recovery action is to formally recommend that business owners implement and maintain a regular patch management program. This aligns with the post-incident activity and lessons-learned phase described in NIST SP 800-61, which emphasizes identifying and communicating corrective actions to prevent recurrence. Documenting and delivering this recommendation directly addresses the vulnerability that led to the incident.

BAsk the business owners to test both systems to ensure the necessary functionality is present

Having business owners test systems is important before returning to production, but it does not address the root cause or prevent a future incident.

CTell the business owners that all needed functionality is present

Telling business owners all needed functionality is present is presumptuous and bypasses the stakeholder validation step they are responsible for performing.

DAsk the business owners when to put the systems back into production

Asking when to put systems back into production skips the critical steps of stakeholder testing and root-cause recommendations that must come first.

ETell the business owners when you will put the systems back into production

Telling business owners when you will put systems back into production bypasses stakeholder input and the required functional testing and validation steps.

Concept tested: Incident response post-recovery lessons learned phase

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident recovery#patch management#post-incident recommendations#system restoration

Community Discussion

No community discussion yet for this question.

Full GCIH Practice