Correct answer: C
The incident response lifecycle runs in sequence: containment, eradication, recovery,
post-incident. All the actions described collectively constitute eradication. Recovery
is the next phase: restoring affected systems from clean backups or reimaged baselines,
under elevated monitoring. Recovery cannot safely begin before eradication is verified.
- AContainment precedes eradication; the team has already passed through it.
- BDetection and analysis is the second phase, occurring at the beginning.
- DPost-incident activities occur only after recovery is complete.
The SSCP guide explains every answer the same way. 162 questions, grouped
by domain.