After a ransomware incident, systems were wiped and restored from clean images. The IR lead needs recovery validation that confirms the adversary cannot immediately regain access. Which action best supports this validation?
Select an answer to reveal the explanation.
Short Explanation
Think of recovery like re-opening a store: you don't just unlock the door and hope. Sweep your restored hosts for indicators and make sure EDR is actually enforcing policy, because an adversary with persistence will be back before you blink. If the checks are clean, you've got a much better shot at staying closed.
Full Explanation
Recovery validation proves the same adversary cannot immediately re-enter, not merely that a host boots. IOC sweeps search for known artifacts such as hashes, registry keys, domains, or process patterns from the incident, while EDR policy checks confirm detection and blocking rules are active on the restored image. These checks target persistence and control failure, common causes of reinfection. A clean image can still fail if an original account, scheduled task, or firewall exception remains. Vulnerability scans support hygiene, but missing CVEs do not prove incident IOCs are absent or endpoint policy is enforced. Hash comparisons verify image integrity, yet an intact image can still contain dormant persistence or disabled EDR. NetFlow beaconing alerts detect later activity, but are reactive and may miss initial re-entry under encryption or normal traffic. Exam caveat: CS0-004 expects you to separate validation from scanning, monitoring, and integrity checks when preventing immediate adversary return. Operational check: before service restoration, query IOC matches and confirm EDR heartbeat and policy state.