Incident Eradication
As you learned previously in this chapter, the objective of the containment process is to stop the spread of an incident. The phase after containment is eradication. The objective of eradication is to identify and correct the root cause that led to the incident. Once containment efforts have been implemented successfully, eradication should be appropriately planned and performeThe following are some activities performed during eradication:
- Root cause analysis
- Updating the firewall and anti-virus to address any gaps
- Scanning the system to determine whether any vulnerabilities remain unnoticed
Practice Question Set 5
- As an information security manager, you are required to determine the point from which the recovery point objective is calculateYour best choice would be:
- The point at which incident response is initiated
- As deemed fit by the recovery manager considering the crisis
- Before image restoration
- The point that aligns with the...