05. Incident Eradication, and Recovery (490) Flashcards

1
Q

Incident Eradication

The complete removal of the agent(s) that caused harm in an incident

490

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Incident Eradication

Confidence in complete eradication is not always hight
Incident responders may often take the decision to rebuild a system from scratch

490

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Incident Recovery

2 basic approaches to recovery;

  1. Restoration of damaged files
  2. Bare-metal restore

491

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Incident Remediation

Recovery of systems to exactly the same state before the incident, the issue/vulnerability that lead to the incident is likely to still exist.
Safeguarding is implemented during the recovery which is when recovery turns into remediation

491

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly