MemotivaSecurity+ Flashcards: Incident Response, Digital Forensics, Business Continuity

What is the difference between containment, eradication, and recovery?

Security+ Flashcards: Incident Response, Digital Forensics, Business Continuity

Audio flashcard · 0:23

Nortren·

What is the difference between containment, eradication, and recovery?

0:23

Containment stops the incident from spreading by isolating affected systems through network disconnection, account disabling, or firewall rule changes. Short-term containment acts immediately, while long-term containment maintains operations during investigation. Eradication removes the root cause by deleting malware, closing exploited vulnerabilities, rebuilding compromised systems from clean images, and resetting compromised credentials.
csrc.nist.gov