Following containment of an intrusion that used a stolen service account to move between several systems, the information security manager is planning eradication. A senior engineer proposes resetting the compromised account and reimaging the entry-point server so recovery can begin. The manager judges this insufficient. Which consideration best explains why eradication should go further before recovery starts?
- AThe root cause and full scope of the compromise, including any other accounts or hosts the attacker reached, must be removed or eradication treats only the symptoms. Correct
- BReimaging a single server will not satisfy the recovery time objective agreed for the affected business service in the business impact analysis.
- CReimaging should be deferred until forensic imaging is complete so that evidence of the intrusion is preserved for any later legal action.
- DResetting one account and one server keeps remediation cheaper than rebuilding every host the attacker may have touched during the intrusion.
Why A is correct: An account that moved laterally implies wider footholds; eradicating only the obvious entry point leaves the root cause and undiscovered access in place, so recovery would restore systems while the threat persists.
Why B is wrong: Linking the action to the recovery time objective sounds business-aligned, but the objective concerns how fast service returns, not whether the threat is fully removed, so it misses the real eradication gap.
Why C is wrong: Evidence preservation is a valid concern earlier in the response, but the manager's worry here is incomplete threat removal, not admissibility, so this addresses a different phase of the lifecycle.
Why D is wrong: Cost restraint can look like sound managerial judgement, but choosing the cheaper fix while the attacker's full reach is unknown is precisely the symptom-level remediation the manager rejects.