Study. uk . com
  1. Home
  2. All questions
  3. Question 65

CISSP study material · question 65 of 500

An organisation is writing the mitigation section of its incident response plan for workloads hosted by a cloud provider whose platform contains some incidents automatically. Which two requirements should that section state? Choose two.

  1. Eradication removes attacker-created accounts and the exploited flaws, not only the malware left behind
  2. Eradication completes before any containment action so that volatile evidence is preserved intact
  3. Handlers retain the ability to contain and eradicate by hand even where the provider acts automatically
  4. Containment waits until the provider's automated response has been reviewed by the handling team
Show the answer

Answer: A. Eradication removes attacker-created accounts and the exploited flaws, not only the malware left behind
C. Handlers retain the ability to contain and eradicate by hand even where the provider acts automatically

Eradication strips malware, seized accounts and every exploited flaw, and responders keep manual capability despite automation. Containment precedes eradication to stop the spread, so reversing that order is wrong.

Source: NIST SP 800-61 Rev. 3 (NIST) — SP 800-61r3 > Section 3.2, RS.MI-01 and RS.MI-02

Challenge yourself on this topic → Study as cards