200-201 Question 331
Select 2Your organization’s security team has detected unusual outbound traffic from a corporate workstation, suggesting a potential malware infection. According to the NIST SP 800-61 incident handling process, which of the following actions should the team take during the Containment, Eradication, and Recovery phase?
- A
Isolate the affected workstation from the network to prevent further spread of the infection.
- B
Analyze the root cause of the incident to understand how the infection occurred.
- C
Restore the affected workstation from a clean backup after ensuring the malware has been completely removed.
- D
Notify external stakeholders, such as customers, about the infection immediately.
- E
Conduct a post-incident review to identify lessons learned.
Show answer and explanation
Correct answers: A, C
Explanation
The Containment, Eradication, and Recovery phase of the NIST SP 800-61 incident handling process focuses on limiting the impact of the incident, removing the threat, and restoring systems to normal operation. Isolating the affected workstation prevents further spread of the malware (containment), and restoring it from a clean backup ensures recovery while ensuring the malware is removed during the eradication step. Other actions, such as root cause analysis and post-incident reviews, belong to different phases of the incident handling process.
- A. Correct.
Isolating the affected workstation is a key containment step to prevent the malware from spreading further within the network, as recommended in the Containment phase.
- B. Incorrect.
Analyzing the root cause of the incident is part of the Post-Incident Activity phase, not the Containment, Eradication, and Recovery phase.
- C. Correct.
Restoring the workstation from a clean backup is a critical recovery step after ensuring the malware has been eradicated. This aligns with the Eradication and Recovery phase.
- D. Incorrect.
Notifying external stakeholders is typically part of the Detection or Analysis phase if the incident impacts them directly. However, it is not a primary step in the Containment, Eradication, and Recovery phase.
- E. Incorrect.
Conducting a post-incident review is part of the Post-Incident Activity phase and occurs after containment, eradication, and recovery are complete.