During the eradication phase of a malware incident, a security analyst removes malicious files and cleans registry persistence. What is the MOST critical additional step to prevent reinfection through the same vector?
Patching the exploited vulnerability closes the original entry vector, so the attacker cannot reinfect the host through the same flaw. Removing files and registry persistence alone leaves that vector open, allowing immediate recompromise during or after eradication.
Why this answer
Patching the exploited vulnerability (Option A) is the most critical additional step because it removes the root cause of the infection. Without patching, the same attack vector (e.g., an unpatched SMB vulnerability like EternalBlue) remains open, allowing the malware to reinfect the system immediately after cleanup. Eradication is incomplete if the underlying flaw is not addressed, as the attacker can simply re-exploit the same weakness.
Exam trap
ISC2 often tests the misconception that cleaning or reimaging alone is sufficient, but the trap here is that candidates overlook the need to address the root cause (the vulnerability) to prevent reinfection through the same vector.
How to eliminate wrong answers
Option B is wrong because running a full antivirus scan is a detection and cleanup step, not a preventive measure against reinfection through the same vector; it may miss zero-day or polymorphic malware. Option C is wrong because resetting user passwords addresses credential theft or lateral movement, but does not close the exploited vulnerability (e.g., a remote code execution flaw in a network service). Option D is wrong because reimaging the system with a clean OS removes the malware but does not patch the original vulnerability; the system will be reinfected if reconnected to the same unpatched network.