🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)53 / 147
Question 53 of 147

A SOC team has confirmed a malware infection on several endpoints. They have already isolated the affected hosts from the network and preserved forensic images. The team now needs to remove the malicious files, delete attacker-created accounts, and close the vulnerabilities the attacker exploited before restoring systems to production. According to the NIST incident response workflow, which phase are they entering?

Reviewed for accuracy · Report an issueNext question