After eradicating malware from a compromised server, the SOC has confirmed IOCs such as C2 domains, file hashes, and mutexes. Which action best verifies eradication?
Select an answer to reveal the explanation.
Short Explanation
Think of eradication like cleaning a wound: just patching one spot doesn't prove the infection's gone. You need to sweep every managed endpoint for the confirmed C2 domains, hashes, and mutexes before calling it clean. Don't trust quiet alerts or a re-imaged server to prove the adversary's artifacts are really gone.
Full Explanation
Eradication verification requires positive evidence that known adversary artifacts are absent, not merely that a single host has been cleaned or that monitoring is quiet. After confirmed indicators such as command-and-control domains, file hashes, and mutexes are removed from a known infected server, the analyst should query EDR, SIEM, endpoint logs, or a hunting platform across all managed endpoints for those indicators. This proves lateral movement or persistence artifacts were not left on other systems. Restoring from a backup taken after the intrusion first surfaced is unsafe because the backup may contain the same implant, persistence mechanism, or credential theft artifacts. Relying on twenty-four hours without new EDR alerts is a passive waiting period; detections can be delayed, suppressed, or evaded, and silence does not prove absence of known indicators. Re-imaging the compromised server and updating a scanner template addresses one asset and a vulnerability, not the broader question of whether confirmed adversary artifacts persist elsewhere. Exam caveat: eradication is complete only when defined indicators are actively searched for and cleared across the affected scope. Operational check: export the confirmed indicators into a SIEM or EDR hunt and run a time-bound sweep across all managed endpoints, then document zero matches or list remaining systems for cleanup.