After containing an incident involving compromised administrative credentials, the IR team is in the recovery phase. Which action is MOST critical before returning affected systems to production?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because returning systems without resetting compromised credentials allows the attacker to regain access immediately. All backdoors must be removed and enhanced monitoring deployed to detect any return activity.
Full explanation below image
Full Explanation
C is correct because returning systems without resetting compromised credentials allows the attacker to regain access immediately. All backdoors must be removed and enhanced monitoring deployed to detect any return activity. A is wrong because software updates are good practice but do not address the compromised credentials. B is wrong because user notification may be required but is not the most critical technical step before returning to production. D is wrong because restoring from backup without knowing the initial infection date may restore already-compromised systems.