GSEC Incident Handling and Response Practice Question
A security analyst is responding to a confirmed malware infection on a critical server. The analyst has already contained the infection by isolating the server from the network. According to the incident handling process, which TWO actions should the analyst perform during the eradication phase? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse recovery actions like restoring from backup with eradication actions, which focus on removing the threat and its root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply security patches and updates to the server's operating system and applications.
The correct actions are to identify and remove all malicious files and processes, and to apply security patches and updates. Eradication is the phase where the threat is eliminated from the environment. This includes removing malware and addressing the vulnerability that allowed the infection. Patching ensures that the same attack vector cannot be used again. Restoring from backup, post-incident review, and monitoring are associated with recovery or post-incident activities, not eradication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a post-incident review to document lessons learned.
Why it's wrong here
Conducting a post-incident review is part of the post-incident activity phase, which occurs after the incident is resolved. Eradication is about removing the threat and preventing recurrence. The post-incident review is a separate phase that evaluates the response and identifies improvements. It is not performed during eradication.
- ✓
Apply security patches and updates to the server's operating system and applications.
Why this is correct
Applying security patches and updates is part of eradication because it addresses the vulnerability that may have been exploited. Even if the malware is removed, without patching, the server remains vulnerable to re-infection. Eradication involves not only removing the threat but also eliminating the root cause. Patching is a preventive measure that strengthens the system against future attacks.
- ✗
Restore the server from a known good backup taken before the infection.
Why it's wrong here
Restoring from a backup is part of the recovery phase, not eradication. Eradication focuses on removing the threat and its root cause. Recovery involves bringing systems back into production, often by restoring from backups. While restoration can be a way to eradicate malware, it is typically considered a recovery step because it returns the system to a functional state. The question specifically asks for eradication actions.
- ✓
Identify and remove all malicious files and processes from the server.
Why this is correct
Identifying and removing malicious files and processes is a core eradication activity. The goal of eradication is to eliminate the threat from the environment. This includes deleting malware, terminating malicious processes, and removing persistence mechanisms. It ensures that the server is clean before restoration. This action directly addresses the malware infection and prevents it from recurring.
- ✗
Monitor network traffic for signs of re-infection.
Why it's wrong here
Monitoring network traffic is part of the detection and analysis or post-incident monitoring, not eradication. While monitoring is important to ensure the threat is gone, it is not an eradication action. Eradication involves active removal of the threat. Monitoring is a passive detective control that can be used to verify the success of eradication but is not the eradication itself.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.