What is eradication in the incident response process?
- A.Formatting all servers, on the basis that the standard requires the incident response plan to be tested every three years at each quarterly ASV scan
- B.Removing the root cause of the incident, such as eliminating malware, closing exploited vulnerabilities, and removing unauthorized access mechanisms
- C.Terminating all user accounts, which v4.0 accommodates by treating any credential rotated at least annually as equivalent to multi-factor authentication for access into the cardholder data environment
- D.Deleting all data, given that the standard exempts incidents detected by a third party from the response process once the acquirer has been notified
Why B is correct
Eradication removes the incident's root cause including malware removal, vulnerability patching, and elimination of unauthorized access methods.
Know someone studying for PCI DSS? Send them this one.