During an security incident, an incident response team has successfully isolated an infected enterprise application server from the internal network. According to standard incident response lifecycle frameworks, which of the following actions represents the primary goal of the eradication phase?
- Eliminating the root cause of the incident by removing malware, revoking compromised credentials, and patching vulnerabilitiesAnswer
- BRestoring affected systems to normal operational status from clean backups and reconnecting network interfaces
- CHolding a post-incident review meeting with stakeholders to document lessons learned and update playbooks
- DAcquiring volatile memory captures and recording forensic timeline details to establish chain of custody
Answer
The primary goal of the eradication phase is eliminating the root cause of the incident by removing malware, revoking compromised credentials, and patching vulnerabilities.
The eradication phase in standard incident response frameworks (e.g., NIST SP 800-61) is dedicated to identifying and removing all components of the threat actor's presence. This includes deleting malware, closing exploited vulnerabilities, and revoking compromised access credentials before proceeding to recovery.
Step-by-Step Solution
Key Concept
Incident Response Lifecycle - Eradication Phase Objectives