GSLC · Question #526
You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it is identified that…
The correct answer is A. Contamination B. Eradication C. Recovery. After an incident is identified, the Containment (labeled here as Contamination), Eradication, and Recovery phases are applied to stop, remove, and restore the affected process.
Question
You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it is identified that this process is providing a way to spammers to perform different types of e-mail attacks. Which of the following phases of the Incident handling process will now be involved in resolving this process and find a solution? Each correct answer represents a part of the solution. Choose all that apply.
Options
- AContamination
- BEradication
- CRecovery
- DIdentification
- EPreparation
How the community answered
(59 responses)- A76% (45)
- D15% (9)
- E8% (5)
Why each option
After an incident is identified, the Containment (labeled here as Contamination), Eradication, and Recovery phases are applied to stop, remove, and restore the affected process.
Containment (presented as 'Contamination' in this question, likely a transcription error for the standard phase name) limits the ongoing damage by restricting or isolating the vulnerable email process so spammers can no longer exploit it during the response.
Eradication removes the root cause of the vulnerability - specifically fixing or disabling the exploitable public relations email auto-response mechanism so it no longer serves as a spam attack vector.
Recovery restores the email process to normal, secure operation after the vulnerability has been eliminated, ensuring business continuity without reintroducing the exploited weakness.
Identification is not part of the solution here because the question explicitly states the problem has already been identified - 'it is identified that this process is providing a way to spammers.'
Preparation is a pre-incident phase focused on building policies, tools, and response capabilities before incidents occur, not on resolving an active ongoing incident.
Concept tested: Incident handling phases - containment, eradication, recovery
Source: https://www.nist.gov/publications/computer-security-incident-handling-guide
Topics
Community Discussion
No community discussion yet for this question.