ある組織の IH&R チームは、組織のネットワークに接続されたホストの 1 つに対する最近のマルウェア攻撃に対処していました。IH&R チームのメンバーである Edwin は、バックアップ メディアから失われたデータを復元する作業に携わっていました。この手順を実行する前に、Edwin はバックアップにマルウェアの痕跡がないことを確認しました。
上記のシナリオで Edwin が実行した IH&R ステップを特定します。
正解:D
Recovery is the IH&R step performed by Edwin in the above scenario. IH&R (Incident Handling and Response) is a process that involves identifying, analyzing, containing, eradicating, recovering from, and reporting on security incidents that affect an organization's network or system. Recovery is the IH&R step that involves restoring the normal operation of the system ornetwork after eradicating the incident. Recovery can include reinstating lost data from the backup media, applying patches or updates, reconfiguring settings, testing functionality, etc. Recovery also involves ensuring that the backup does not have any traces of malware or compromise . Eradication is the IH&R step that involves removing all traces of the incident from the system or network, such as malware, backdoors, compromised files, etc. Incident containment is the IH&R step that involves implementing appropriate measures to stop the infection from spreading to other organizational assets and to prevent further damage to the organization. Notification is the IH&R step that involves informing relevant stakeholders, authorities, or customers about the incident and its impact.