GSEC Incident Handling and Response Practice Question
During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?
⚠ Common exam trap
Candidates often choose only one action (like patching) while ignoring that eradication must address the attacker's persistence mechanisms, such as compromised credentials and backdoors, to be truly effective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resetting compromised user passwords
Eradication aims to completely remove the adversary's presence. Simply deleting a file is rarely sufficient; attackers often leave multiple persistence mechanisms or backdoors. By resetting credentials, patching the underlying vulnerability, and re-imaging systems, the organization ensures that the attacker cannot easily return, effectively closing the window of opportunity that allowed the initial unauthorized access to occur and persist.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Resetting compromised user passwords
Why this is correct
If an attacker has stolen credentials, simply removing the backdoor is insufficient because the attacker can still authenticate using the compromised account. Resetting passwords is a mandatory eradication step to prevent the adversary from regaining access via legitimate authentication channels after the malicious artifacts are removed.
- ✗
Analyzing the memory dump for malware signatures
Why it's wrong here
Analyzing a memory dump is an Identification or investigation activity. Eradication is the process of removing the threat from the environment. Once the threat is identified, the focus shifts to neutralizing it, not continuing the analysis, which would have happened in the earlier identification and forensic investigation phases.
- ✓
Patching the vulnerability used for initial access
Why this is correct
Eradication must address the root cause of the incident. If the vulnerability that allowed the initial entry remains unpatched, the attacker or others will simply re-exploit it. Patching ensures the environment is hardened, preventing the attacker from re-entering through the same path that was used during the compromise.
- ✓
Re-imaging infected systems from a known-good source
Why this is correct
Re-imaging is the most reliable way to remove sophisticated malware that may have hidden itself deep within the operating system. Because attackers can modify system files and kernel drivers, simple file deletion is often ineffective, making re-imaging from a trusted source the best way to ensure complete eradication.
- ✗
Drafting an incident report for executive leadership
Why it's wrong here
Drafting an incident report is a task for the post-incident activity or documentation phase. While reporting is important for stakeholders, it does not contribute to the actual removal of the adversary's access or the restoration of the secure state of the systems, which is the sole focus of eradication.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.