asked 59.1k views
2 votes
What incident response activity focuses on removing any artifacts of the incident that may remain on the organization's network?

A. Containment
B. Recovery
C. Post-Incident Activities
D. Eradication

1 Answer

4 votes

Final answer:

The incident response activity that removes remnants of a network incident is Eradication, which comes after Containment and before Recovery. Hence, option D is the correct answer.

Step-by-step explanation:

The incident response activity that focuses on removing any artifacts of the incident that may remain on the organization's network is Eradication. After Containment efforts have isolated the threat to prevent it from spreading, and before the Recovery phase where normal operations are restored, Eradication is essential as it involves the elimination of the components of the incident, such as deleting malware, disabling breached user accounts, and updating security policies to prevent future incidents. It ensures that the threat is completely removed from the environment.

answered
User Liam Gray
by
8.4k points
Welcome to Qamnty — a place to ask, share, and grow together. Join our community and get real answers from real people.