SY0-501 · Question #502
A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEXT according to the…
The correct answer is A. Restore lost data from a backup. Following the containment and eradication of a security incident, the next crucial step in the incident response process is to restore system functionality and data integrity to normal operations.
Question
A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEXT according to the incident response process?
Options
- ARestore lost data from a backup.
- BWipe the system.
- CDocument the lessons learned.
- DDetermine the scope of impact.
How the community answered
(55 responses)- A84% (46)
- B5% (3)
- C2% (1)
- D9% (5)
Why each option
Following the containment and eradication of a security incident, the next crucial step in the incident response process is to restore system functionality and data integrity to normal operations.
After containing an infected system and eradicating the malicious process, the incident response process moves to the Recovery phase, where restoring lost or corrupted data from a clean backup is essential to bring the system back to a secure and operational state.
Wiping the system is generally part of the Eradication phase to remove all traces of the compromise, which occurs before the Recovery phase where data is restored.
Documenting lessons learned is a post-incident activity that occurs after the recovery and verification of the system's operational status, not immediately after containment and eradication.
Determining the scope of impact is part of the Identification phase, which typically happens much earlier in the incident response process, before containment and eradication.
Concept tested: Incident response process phases (recovery)
Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.