nerdexam
CompTIA

SY0-501 · Question #502

A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEXT according to the…

The correct answer is A. Restore lost data from a backup. Following the containment and eradication of a security incident, the next crucial step in the incident response process is to restore system functionality and data integrity to normal operations.

Submitted by rohit_dlh· Mar 4, 2026Security operations

Question

A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEXT according to the incident response process?

Options

  • ARestore lost data from a backup.
  • BWipe the system.
  • CDocument the lessons learned.
  • DDetermine the scope of impact.

How the community answered

(55 responses)
  • A
    84% (46)
  • B
    5% (3)
  • C
    2% (1)
  • D
    9% (5)

Why each option

Following the containment and eradication of a security incident, the next crucial step in the incident response process is to restore system functionality and data integrity to normal operations.

ARestore lost data from a backup.Correct

After containing an infected system and eradicating the malicious process, the incident response process moves to the Recovery phase, where restoring lost or corrupted data from a clean backup is essential to bring the system back to a secure and operational state.

BWipe the system.

Wiping the system is generally part of the Eradication phase to remove all traces of the compromise, which occurs before the Recovery phase where data is restored.

CDocument the lessons learned.

Documenting lessons learned is a post-incident activity that occurs after the recovery and verification of the system's operational status, not immediately after containment and eradication.

DDetermine the scope of impact.

Determining the scope of impact is part of the Identification phase, which typically happens much earlier in the incident response process, before containment and eradication.

Concept tested: Incident response process phases (recovery)

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf

Topics

#incident response#recovery phase#eradication#malware remediation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice