- Home
- All questions
- Question 65
CISSP study material · question 65 of 500
An organisation is writing the mitigation section of its incident response plan for workloads hosted by a cloud provider whose platform contains some incidents automatically. Which two requirements should that section state? Choose two.
Show the answer
Answer: A. Eradication removes attacker-created accounts and the exploited flaws, not only the malware left behind
C. Handlers retain the ability to contain and eradicate by hand even where the provider acts automatically
Eradication strips malware, seized accounts and every exploited flaw, and responders keep manual capability despite automation. Containment precedes eradication to stop the spread, so reversing that order is wrong.
Source: NIST SP 800-61 Rev. 3 (NIST) — SP 800-61r3 > Section 3.2, RS.MI-01 and RS.MI-02