nerdexam
CompTIA

CAS-002 · Question #676

Elaine is conducting an AAR after a hacker managed to breach the network security and steal data from the database server. Which of the following should not be part of the AAR?

The correct answer is D. Assessing who is responsible for the breach. Assessing blame is counter productive. You do not want blame to be part of the process of the Answer option C is incorrect. Any biases will keep you from seeing all the possible solutions. It is impossible to conduct a good AAR unless you are unbiased. Answer option A is…

Enterprise Security

Question

Elaine is conducting an AAR after a hacker managed to breach the network security and steal data from the database server. Which of the following should not be part of the AAR?

Options

  • AGetting input from multiple perspectives
  • BDescribe what happened
  • CRemain unbiased
  • DAssessing who is responsible for the breach

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    5% (2)
  • D
    92% (35)

Explanation

Assessing blame is counter productive. You do not want blame to be part of the process of the Answer option C is incorrect. Any biases will keep you from seeing all the possible solutions. It is impossible to conduct a good AAR unless you are unbiased. Answer option A is incorrect. The more perspectives that provide input, the more likely that creative answers are likely to be found. Answer option B is incorrect. The first step in an AAR is to accurately and completely describe

Topics

#after action review#incident response#blame-free analysis#security audit process

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice