Eradication is the phase of incident response where the incident team removes the threat from the affected systems and restores them to a secure state. If this phase is not successful, the malware may persist or reappear on the systems, causing further damage or compromise. Therefore, eradication is the correct answer.
[References:, https://www.securitymetrics.com/blog/6-phases-incident-response-plan, https://www.atlassian.com/incident-management/incident-response, https://eccouncil.org/cybersecurity-exchange/incident-handling/what-is-incident-response-life-cycle/, , , , , , ]
Submit