GCIH · Question #364
You are in the process of recovering from an incident where a web server and database server were severely compromised due to a lack of patching. Both servers have been rebuilt and fully patched…
The correct answer is A. Recommend that the business owners make sure they keep their systems patched up to date. After rebuilding and patching compromised servers, the most important step in incident response is to address the root cause by formally recommending ongoing patch management to business owners. This aligns with the lessons-learned phase of incident response frameworks.
Question
You are in the process of recovering from an incident where a web server and database server were severely compromised due to a lack of patching. Both servers have been rebuilt and fully patched. Which of the following choices BEST describes what you should do next?
Options
- ARecommend that the business owners make sure they keep their systems patched up to date
- BAsk the business owners to test both systems to ensure the necessary functionality is present
- CTell the business owners that all needed functionality is present
- DAsk the business owners when to put the systems back into production
- ETell the business owners when you will put the systems back into production
How the community answered
(44 responses)- A73% (32)
- B5% (2)
- C2% (1)
- D7% (3)
- E14% (6)
Why each option
After rebuilding and patching compromised servers, the most important step in incident response is to address the root cause by formally recommending ongoing patch management to business owners. This aligns with the lessons-learned phase of incident response frameworks.
The root cause of the compromise was a lack of patching, so the most critical post-recovery action is to formally recommend that business owners implement and maintain a regular patch management program. This aligns with the post-incident activity and lessons-learned phase described in NIST SP 800-61, which emphasizes identifying and communicating corrective actions to prevent recurrence. Documenting and delivering this recommendation directly addresses the vulnerability that led to the incident.
Having business owners test systems is important before returning to production, but it does not address the root cause or prevent a future incident.
Telling business owners all needed functionality is present is presumptuous and bypasses the stakeholder validation step they are responsible for performing.
Asking when to put systems back into production skips the critical steps of stakeholder testing and root-cause recommendations that must come first.
Telling business owners when you will put systems back into production bypasses stakeholder input and the required functional testing and validation steps.
Concept tested: Incident response post-recovery lessons learned phase
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.