nerdexam
GIAC

GCIH · Question #490

A server was infected by malware and controlled by an attacker for six months. The server was recovered and returned to production. Which of the following would provide the most effective…

The correct answer is A. A root cause analysis of the vector and methods of attack. The attacker will likely try to return through the same channels he tried initially, so a good place to start for a monitoring service is to review the root cause of the attack, and create signatures for those IOCs or artifacts. Using the baseline operating system would…

Incident Response & Cyber Kill Chain

Question

A server was infected by malware and controlled by an attacker for six months. The server was recovered and returned to production. Which of the following would provide the most effective information to build a post-incident monitoring service for this server?

Options

  • AA root cause analysis of the vector and methods of attack
  • BThe network and host firewall rules in place when the attack began
  • CThe operating system files installed on the server
  • DThe Acceptable Use policy and a list of organization-tested applications

How the community answered

(19 responses)
  • A
    53% (10)
  • B
    11% (2)
  • C
    26% (5)
  • D
    11% (2)

Explanation

The attacker will likely try to return through the same channels he tried initially, so a good place to start for a monitoring service is to review the root cause of the attack, and create signatures for those IOCs or artifacts. Using the baseline operating system would generate many false

Topics

#post-incident monitoring#root cause analysis#threat intelligence#recovery planning

Community Discussion

No community discussion yet for this question.

Full GCIH Practice