712-50 · Question #297
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief…
The correct answer is D. Follow-up. This phase, often called "lessons learned," "post-incident review," or "post-incident activity," involves analyzing the incident and response to identify root causes, gaps, and weaknesses. It is focused on improving future incident response efforts and implementing changes-such…
Question
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team. What phase of the response provides measures to reduce the likelihood of an incident from recurring?
Options
- AResponse
- BInvestigation
- CRecovery
- DFollow-up
How the community answered
(44 responses)- A2% (1)
- B5% (2)
- C9% (4)
- D84% (37)
Explanation
This phase, often called "lessons learned," "post-incident review," or "post-incident activity," involves analyzing the incident and response to identify root causes, gaps, and weaknesses. It is focused on improving future incident response efforts and implementing changes-such as updated policies, controls, and training-to prevent recurrence of similar incidents. This ensures continuous improvement of security posture after recovery from the incident.
Topics
Community Discussion
No community discussion yet for this question.