712-50 Exam QuestionsBrowse all questions from this exam

712-50 Exam - Question 91


Your incident handling manager detects a virus attack in the network of your company. You develop a signature based on the characteristics of the detected virus.

Which of the following phases in the incident handling process will utilize the signature to resolve this incident?

Show Answer
Correct Answer: A

The eradication phase involves eliminating the components of the incident, such as deleting malware or disabling breached user accounts. Developing and using a signature based on the characteristics of the detected virus is a key part of this phase, as it helps identify and remove the virus from affected systems.

Discussion

3 comments
Sign in to comment
Perseus_68Option: A
Mar 3, 2024

There is no Identification phase in IR under NIST, Prep, detection and analysis, Containment, eradication and recovery, and post. Eradication involves using AV tools or manual removal techniques. And, the virus has already been identified.

musagulOption: D
Feb 22, 2024

I think the correct answer is Indetification. If the answer is A, can someone tell me according to what, identification of suspicious is going to be done? Of course to signature...

johndoe69Option: A
Jun 3, 2024

Reference: NIST Special Publication 800-61 Revision 2: According to NIST, the eradication phase involves eliminating the components of the incident, such as deleting malware or disabling breached user accounts. Developing and using a signature based on the characteristics of the detected virus is a key part of this phase, as it helps identify and remove the virus from affected systems (NIST, 2012). SANS Institute Incident Handling Step-by-Step: The SANS Institute also outlines that during the eradication phase, signatures and other detection tools are used to ensure that all instances of the threat are identified and removed from the network (SANS, 2019).