nerdexam
GIAC

GCIH · Question #93

In which of the following steps of the incident handling processes does the Incident Handler make sure that all business processes and functions are back to normal and then also wants to monitor the…

The correct answer is C. Recovery. The Recovery phase of incident handling restores systems to normal operations and includes ongoing monitoring to detect recompromise.

Incident Response & Cyber Kill Chain

Question

In which of the following steps of the incident handling processes does the Incident Handler make sure that all business processes and functions are back to normal and then also wants to monitor the system or processes to ensure that the system is not compromised again?

Options

  • AEradication
  • BLesson Learned
  • CRecovery
  • DContainment

How the community answered

(29 responses)
  • B
    3% (1)
  • C
    93% (27)
  • D
    3% (1)

Why each option

The Recovery phase of incident handling restores systems to normal operations and includes ongoing monitoring to detect recompromise.

AEradication

Eradication focuses solely on removing the root cause of the incident (malware, backdoors, vulnerabilities) but does not involve restoring business processes to normal or post-restoration monitoring.

BLesson Learned

Lessons Learned is a post-incident documentation and review phase conducted after full recovery, focused on improving future response, not on restoring services.

CRecoveryCorrect

Recovery is the phase where the incident handler restores all affected systems and business processes to their normal operational state. After restoration, the handler actively monitors the environment to confirm the threat is fully resolved and that no reinfection or recompromise occurs. This distinguishes Recovery from Eradication, which only removes the threat without restoring services or adding monitoring.

DContainment

Containment limits the spread and impact of an incident in progress but does not restore business functions or involve monitoring for recompromise.

Concept tested: Incident response lifecycle - Recovery phase

Source: https://www.nist.gov/publications/computer-security-incident-handling-guide

Topics

#incident handling#recovery phase#business continuity#incident response lifecycle

Community Discussion

No community discussion yet for this question.

Full GCIH Practice