GSLC · Question #459
You work as an Incident handling manager for Orangesect Inc. You detect a virus attack incident in the network of your company. You develop a signature based on the characteristics of the detected vir
The correct answer is D. Eradication. The Eradication phase uses artifacts like virus signatures to detect and remove all traces of a threat from affected systems.
Question
You work as an Incident handling manager for Orangesect Inc. You detect a virus attack incident in the network of your company. You develop a signature based on the characteristics of the detected virus. Which of the following phases in the Incident handling process will utilize the signature to resolve this incident?
Options
- AContainment
- BRecovery
- CIdentification
- DEradication
How the community answered
(34 responses)- A3% (1)
- C6% (2)
- D91% (31)
Why each option
The Eradication phase uses artifacts like virus signatures to detect and remove all traces of a threat from affected systems.
Containment focuses on isolating and limiting the spread of an incident, not on applying signatures to actively remove malicious code.
Recovery involves restoring systems to normal operation after the threat has already been removed during eradication, not the removal itself.
Identification is the phase where the incident is detected and its scope is assessed, which already occurred before the virus signature was developed.
Eradication is the phase in which the root cause of an incident is fully eliminated from all affected systems. A signature developed from detected virus characteristics is applied during this phase to scan for and remove every instance of the malware, ensuring the threat is completely purged from the network before recovery begins.
Concept tested: Eradication phase role in incident handling
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.