nerdexam
GIAC

GSLC · Question #526

You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it is identified that…

The correct answer is A. Contamination B. Eradication C. Recovery. After an incident is identified, the Containment (labeled here as Contamination), Eradication, and Recovery phases are applied to stop, remove, and restore the affected process.

Security Operations & Incident Response Leadership

Question

You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it is identified that this process is providing a way to spammers to perform different types of e-mail attacks. Which of the following phases of the Incident handling process will now be involved in resolving this process and find a solution? Each correct answer represents a part of the solution. Choose all that apply.

Options

  • AContamination
  • BEradication
  • CRecovery
  • DIdentification
  • EPreparation

How the community answered

(59 responses)
  • A
    76% (45)
  • D
    15% (9)
  • E
    8% (5)

Why each option

After an incident is identified, the Containment (labeled here as Contamination), Eradication, and Recovery phases are applied to stop, remove, and restore the affected process.

AContaminationCorrect

Containment (presented as 'Contamination' in this question, likely a transcription error for the standard phase name) limits the ongoing damage by restricting or isolating the vulnerable email process so spammers can no longer exploit it during the response.

BEradicationCorrect

Eradication removes the root cause of the vulnerability - specifically fixing or disabling the exploitable public relations email auto-response mechanism so it no longer serves as a spam attack vector.

CRecoveryCorrect

Recovery restores the email process to normal, secure operation after the vulnerability has been eliminated, ensuring business continuity without reintroducing the exploited weakness.

DIdentification

Identification is not part of the solution here because the question explicitly states the problem has already been identified - 'it is identified that this process is providing a way to spammers.'

EPreparation

Preparation is a pre-incident phase focused on building policies, tools, and response capabilities before incidents occur, not on resolving an active ongoing incident.

Concept tested: Incident handling phases - containment, eradication, recovery

Source: https://www.nist.gov/publications/computer-security-incident-handling-guide

Topics

#incident handling#eradication#recovery#email attack response

Community Discussion

No community discussion yet for this question.

Full GSLC Practice