-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating
CompTIA CySA+ Study Guide: Exam CS0-002
By :
Once the cybersecurity team successfully contains an incident, it is time to move on to the eradication phase of the response. The primary purpose of eradication is to remove any of the artifacts of the incident that may remain on the organization’s network. This could include the removal of any malicious code from the network, the sanitization of compromised media, and the securing of compromised user accounts.
The recovery phase of incident response focuses on restoring normal operations and correcting security control deficiencies that may have led to the attack. This could include rebuilding and patching systems, reconfiguring firewalls, updating malware signatures, and similar activities. The goal of recovery is not just to rebuild the organization’s network but to do so in a manner that reduces the likelihood of a successful future attack.
Change the font size
Change margin width
Change background colour