During the Recovery phase of an incident, the team restores a compromised server from a backup taken 48 hours before the incident was detected. The attacker had been present for 5 days before detection. What critical problem exists with this recovery approach?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the attacker was present for 5 days before detection, meaning a backup taken 48 hours before detection still falls within the attacker's dwell period (3 days after initial compromise); restoring this backup may restore the attacker's persistence mechanisms alongside legitimate data. A is wrong because backup restore time is an operational concern, not a security problem.
Full explanation below image
Full Explanation
B is correct because the attacker was present for 5 days before detection, meaning a backup taken 48 hours before detection still falls within the attacker's dwell period (3 days after initial compromise); restoring this backup may restore the attacker's persistence mechanisms alongside legitimate data. A is wrong because backup restore time is an operational concern, not a security problem. C is wrong because backup admissibility as forensic evidence is not the issue here; the problem is restoring attacker artifacts. D is wrong because backups taken before an incident can be used for recovery if they predate the compromise; the problem here is that the backup does NOT predate the compromise.