nerdexam
GIAC

GCIH · Question #390

Regardless of the initial compromise or type of incident, which step is always a good practice during the Recovery phase of the Incident Handling Process?

The correct answer is D. Have the data owner verify the system before it is placed back in production. Validating the host/network/application/etc. will always take place during Recovery and the best- case scenario is to have the data owner validate the system. Implementing centralized logging and monitoring for C2 are actions that may take place during Recovery, but the context…

Incident Response & Cyber Kill Chain

Question

Regardless of the initial compromise or type of incident, which step is always a good practice during the Recovery phase of the Incident Handling Process?

Options

  • AImplement centralized logging for hosts that were compromised
  • BMonitor outbound connections for C2-related traffic
  • CValidate the executive summary before sending it to the stakeholders
  • DHave the data owner verify the system before it is placed back in production

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    92% (24)

Explanation

Validating the host/network/application/etc. will always take place during Recovery and the best- case scenario is to have the data owner validate the system. Implementing centralized logging and monitoring for C2 are actions that may take place during Recovery, but the context of the incident would dictate of these actions are appropriate or unnecessary. It is much more likely that monitoring for C2 or implementing targeted logging for compromised hosts would take place in the Containment or Eradication phases before Validating the report would take place during the Lessons Learned phase, prior to the meeting.

Topics

#incident handling#recovery phase#data owner verification#IR process

Community Discussion

No community discussion yet for this question.

Full GCIH Practice