A SOC analyst has confirmed a malware infection, isolated the affected server, and blocked command-and-control traffic. The containment step is complete, and no evidence preservation issues remain. What should happen next in the incident response process?
Select an answer to reveal the explanation.
Short Explanation
Think of incident response like triage: once you stop the bleeding, you don't start rehab. You clear the cause first. That's eradication - remove the malware, kill the persistence, and close the hole before recovery begins.
Full Explanation
In the NIST incident response lifecycle, containment stabilizes the environment, but it does not remove the underlying cause. The next phase is eradication, where the analyst removes malware, disables abused accounts, terminates malicious processes, eliminates persistence mechanisms, and patches exploited weaknesses. Only after eradication is verified can systems be restored or returned to production without re-infection. Recovery activities are performed after the threat has been removed; restoring from backups or rebuilding hosts too early can reintroduce the same compromise. Post-incident review belongs at the end of the response, after the incident is closed, and focuses on metrics, root cause, and process improvements rather than immediate threat removal. Detection and analysis precedes containment, because evidence must be collected, scope determined, and indicators validated before isolation or blocking actions are taken. Exam caveat: CS0-004 questions often ask for the next phase, not the overall goal; if the stem says containment is complete, do not jump to recovery or lessons learned. Operational check: before moving a host out of containment, confirm the malicious binary is deleted, scheduled tasks and registry autostarts are clean, the exploited service is patched, and monitoring shows no recurrence.