GCIH · Question #448
After a system that was compromised in an incident is brought back into production, which part of the incident handling process must be done?
The correct answer is B. Monitor for compromise. If the eradication was not complete or the infection vector was not closed off, the earlier you detect re-infection, the better off everyone is. It is also politically better if the handlers detect the problem and show up to fix it than if the problem comes to light because…
Question
After a system that was compromised in an incident is brought back into production, which part of the incident handling process must be done?
Options
- AWipe and reinstall from original media
- BMonitor for compromise
- CCreate a baseline
- DCreate a new, clean, backup
- EReinstall from last uncompromised backup
How the community answered
(21 responses)- A5% (1)
- B90% (19)
- C5% (1)
Explanation
If the eradication was not complete or the infection vector was not closed off, the earlier you detect re-infection, the better off everyone is. It is also politically better if the handlers detect the problem and show up to fix it than if the problem comes to light because business operations are affected. This is a serious problem. Many times, handlers take some shortcut along the way, or there is something you never discovered about the attack vector, and the problem comes back.
Topics
Community Discussion
No community discussion yet for this question.