59.1k views
2 votes
What incident response activity focuses on removing any artifacts of the incident that may remain on the organization's network?

A. Containment
B. Recovery
C. Post-Incident Activities
D. Eradication

1 Answer

4 votes

Final answer:

The incident response activity that removes remnants of a network incident is Eradication, which comes after Containment and before Recovery. Hence, option D is the correct answer.

Step-by-step explanation:

The incident response activity that focuses on removing any artifacts of the incident that may remain on the organization's network is Eradication. After Containment efforts have isolated the threat to prevent it from spreading, and before the Recovery phase where normal operations are restored, Eradication is essential as it involves the elimination of the components of the incident, such as deleting malware, disabling breached user accounts, and updating security policies to prevent future incidents. It ensures that the threat is completely removed from the environment.

User Liam Gray
by
8.4k points