Medium1 markMultiple Choice
Area II: SecurityIncident ResponseArea II

CPA · Question 59 · Area II: Security

An auditor is reviewing the 'Incident Response Plan'. Which phase should occur immediately after 'Containment'?

Answer options:

A.

Preparation

B.

Identification

C.

Eradication

D.

Recovery

How to approach this question

Memorize the PICERL cycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).

Full Answer

C.Eradication✓ Correct
Eradication
Once the threat is contained (stopped from spreading), the root cause must be eradicated (removed) before recovery can begin.

Common mistakes

Skipping to Recovery before Eradication.

Practice the full CPA ISC Practice Exam 2

82 questions · hints · full answers · grading

More questions from this exam