Recall & Review
beginner
What is the main goal of the eradication phase in cybersecurity incident response?
The main goal of eradication is to completely remove the cause of the security incident, such as malware or unauthorized access, to prevent it from happening again.
Click to reveal answer
beginner
What does the recovery phase focus on after a cybersecurity incident?
The recovery phase focuses on restoring and validating system functionality to normal operations while ensuring that vulnerabilities are fixed and no threats remain.
Click to reveal answer
intermediate
Why is it important to monitor systems after recovery?
Monitoring after recovery helps detect any signs of the incident reoccurring or new threats, ensuring the environment remains secure.
Click to reveal answer
intermediate
Name two common actions taken during eradication.
Common actions include removing malware, closing exploited vulnerabilities, and deleting unauthorized user accounts.
Click to reveal answer
beginner
How does recovery differ from eradication in incident response?
Eradication removes the threat, while recovery restores systems to normal operation and ensures they are safe to use.
Click to reveal answer
What is the first step in the eradication phase?
✗ Incorrect
Eradication begins by identifying and removing the root cause, such as malware or vulnerabilities.
During recovery, what is a key activity?
✗ Incorrect
Recovery focuses on restoring systems to normal operation after threats are removed.
Why is it important to validate systems during recovery?
✗ Incorrect
Validation confirms that threats are removed and systems are safe to use.
Which of the following is NOT part of eradication?
✗ Incorrect
Restoring backups is part of recovery, not eradication.
What should be done after recovery to prevent future incidents?
✗ Incorrect
Monitoring and updating security helps prevent recurrence of incidents.
Explain the difference between eradication and recovery in incident response.
Think about what happens first and what happens after removing the threat.
You got /3 concepts.
List key actions taken during the eradication phase.
Focus on how the threat is eliminated.
You got /3 concepts.