05. Incident Eradication, and Recovery (490) Flashcards
1
Q
Incident Eradication
The complete removal of the agent(s) that caused harm in an incident
490
A
2
Q
Incident Eradication
Confidence in complete eradication is not always hight
Incident responders may often take the decision to rebuild a system from scratch
490
A
3
Q
Incident Recovery
2 basic approaches to recovery;
- Restoration of damaged files
- Bare-metal restore
491
A
4
Q
Incident Remediation
Recovery of systems to exactly the same state before the incident, the issue/vulnerability that lead to the incident is likely to still exist.
Safeguarding is implemented during the recovery which is when recovery turns into remediation
491
A
5
Q
A