Reimaging the disk is a recovery activity because it restores the compromised endpoint to a trusted operational state after malicious activity has been identified and contained. Reimaging replaces the affected operating environment with a known-good system image, removing uncertainty about hidden persistence mechanisms, modified system files, unauthorized software, or other residual effects of compromise.
Verification that malicious activity occurred belongs to the detection and analysis stage. Taking the system offline is a containment measure intended to prevent additional propagation, command-and-control communication, or damage. Writing the final report occurs during post-incident documentation and lessons-learned activities rather than operational restoration.
NIST's Recover function focuses on restoring affected assets and operations and verifying that restored systems are suitable for return to normal business use. A clean reimage is particularly appropriate where the integrity of the compromised operating system cannot be reliably established through selective malware removal.
After rebuilding, analysts should verify configuration, patch levels, security controls, credentials, and monitoring before reconnecting the machine to production.
Study Guide Reference: Incident Response and Management → Recovery → Reimaging → Known-Good Baselines → Restoration Validation → Return to Production.