Incident Handling & Response lifecycle scenario analysis
Select the correct answer:
Recovery is the IH&R phase where affected systems and data are restored to normal, secure operation. This includes reinstating lost data from verified clean backups, rebuilding compromised systems, and validating that services are fully functional before returning them to production.
During recovery, the IH&R team restores data from backup media that has been scanned and confirmed free of malware. Systems are rebuilt or patched, security configurations are hardened, and each restored service is tested to ensure integrity. The team verifies that the threat has been completely eradicated before any system goes back online.
Without proper recovery, an organization risks prolonged downtime, data loss, and even reinfection. A careful recovery process ensures business continuity while maintaining security. Restoring from a compromised backup could reintroduce the very malware that caused the incident.
After a ransomware attack encrypts a company's file server, the IH&R team first contains and eradicates the threat. During recovery, they restore files from last week's verified backup tapes, confirm no malware traces exist in the backups, rebuild the server with updated security patches, and gradually bring services back online while monitoring for anomalies.
Recovery comes after eradication. The critical distinction is: eradication removes the threat, while recovery restores systems and data to normal operation. Always verify that backups are clean before restoring — a contaminated backup defeats the entire purpose of recovery.