nerdexam
GIAC

GCIH · Question #448

After a system that was compromised in an incident is brought back into production, which part of the incident handling process must be done?

The correct answer is B. Monitor for compromise. If the eradication was not complete or the infection vector was not closed off, the earlier you detect re-infection, the better off everyone is. It is also politically better if the handlers detect the problem and show up to fix it than if the problem comes to light because…

Incident Response & Cyber Kill Chain

Question

After a system that was compromised in an incident is brought back into production, which part of the incident handling process must be done?

Options

  • AWipe and reinstall from original media
  • BMonitor for compromise
  • CCreate a baseline
  • DCreate a new, clean, backup
  • EReinstall from last uncompromised backup

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    90% (19)
  • C
    5% (1)

Explanation

If the eradication was not complete or the infection vector was not closed off, the earlier you detect re-infection, the better off everyone is. It is also politically better if the handlers detect the problem and show up to fix it than if the problem comes to light because business operations are affected. This is a serious problem. Many times, handlers take some shortcut along the way, or there is something you never discovered about the attack vector, and the problem comes back.

Topics

#incident handling#post-recovery monitoring#eradication#reinfection detection

Community Discussion

No community discussion yet for this question.

Full GCIH Practice