nerdexam
GIAC

GSLC · Question #459

You work as an Incident handling manager for Orangesect Inc. You detect a virus attack incident in the network of your company. You develop a signature based on the characteristics of the detected vir

The correct answer is D. Eradication. The Eradication phase uses artifacts like virus signatures to detect and remove all traces of a threat from affected systems.

Security Operations & Incident Response Leadership

Question

You work as an Incident handling manager for Orangesect Inc. You detect a virus attack incident in the network of your company. You develop a signature based on the characteristics of the detected virus. Which of the following phases in the Incident handling process will utilize the signature to resolve this incident?

Options

  • AContainment
  • BRecovery
  • CIdentification
  • DEradication

How the community answered

(34 responses)
  • A
    3% (1)
  • C
    6% (2)
  • D
    91% (31)

Why each option

The Eradication phase uses artifacts like virus signatures to detect and remove all traces of a threat from affected systems.

AContainment

Containment focuses on isolating and limiting the spread of an incident, not on applying signatures to actively remove malicious code.

BRecovery

Recovery involves restoring systems to normal operation after the threat has already been removed during eradication, not the removal itself.

CIdentification

Identification is the phase where the incident is detected and its scope is assessed, which already occurred before the virus signature was developed.

DEradicationCorrect

Eradication is the phase in which the root cause of an incident is fully eliminated from all affected systems. A signature developed from detected virus characteristics is applied during this phase to scan for and remove every instance of the malware, ensuring the threat is completely purged from the network before recovery begins.

Concept tested: Eradication phase role in incident handling

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident handling#eradication phase#virus signature#malware response

Community Discussion

No community discussion yet for this question.

Full GSLC Practice