Study. uk . com
  1. Home
  2. All questions
  3. Question 498

CompTIA Security+ study material · question 498 of 611

After eradication and recovery, what does NIST expect the team to do?

  1. Close the incident and archive the ticket
  2. Monitor to confirm the adversary has not returned
  3. Rotate all organisational credentials
  4. Rescan for unrelated vulnerabilities
Show the answer

Answer: B. Monitor to confirm the adversary has not returned

Recovery restores service; monitoring afterwards is what shows the eradication actually removed the cause.

Source: NIST SP 800-61 Rev. 2 (NIST) — SP 800-61 Rev. 2 § 3.3.4 Eradication and Recovery

Challenge yourself on this topic → Study as cards