nerdexam
CompTIA

CAS-003 · Question #6

Legal authorities notify a company that its network has been compromised for the second time in two years. The investigation shows the attackers were able to use the same vulnerability on different…

The correct answer is B. Lessons learned. A lessons learned process formally documents findings from past incidents and applies them to improve defenses, which would have allowed the team to address the repeated vulnerability before the second attack.

Enterprise Security Operations

Question

Legal authorities notify a company that its network has been compromised for the second time in two years. The investigation shows the attackers were able to use the same vulnerability on different systems in both attacks. Which of the following would have allowed the security team to use historical information to protect against the second attack?

Options

  • AKey risk indicators
  • BLessons learned
  • CRecovery point objectives
  • DTabletop exercise

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    92% (34)
  • C
    3% (1)

Why each option

A lessons learned process formally documents findings from past incidents and applies them to improve defenses, which would have allowed the team to address the repeated vulnerability before the second attack.

AKey risk indicators

Key risk indicators are metrics used to monitor ongoing risk levels and do not capture or apply historical incident-specific vulnerability details.

BLessons learnedCorrect

Lessons learned is a structured post-incident review that captures technical details including exploited vulnerabilities, remediation actions taken, and process gaps. Had the team documented and acted on findings from the first compromise - specifically the vulnerability used - they would have had historical context to detect or block the same attack vector on different systems during the second incident.

CRecovery point objectives

Recovery point objectives define acceptable data loss thresholds for backup and recovery planning and are unrelated to preventing repeated exploitation of a known vulnerability.

DTabletop exercise

Tabletop exercises simulate hypothetical scenarios for training purposes but do not produce or apply historical vulnerability remediation records.

Concept tested: Applying lessons learned to prevent repeated incidents

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#lessons learned#incident response#vulnerability management#historical threat data

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice