CAS-003 · Question #6
Legal authorities notify a company that its network has been compromised for the second time in two years. The investigation shows the attackers were able to use the same vulnerability on different…
The correct answer is B. Lessons learned. A lessons learned process formally documents findings from past incidents and applies them to improve defenses, which would have allowed the team to address the repeated vulnerability before the second attack.
Question
Legal authorities notify a company that its network has been compromised for the second time in two years. The investigation shows the attackers were able to use the same vulnerability on different systems in both attacks. Which of the following would have allowed the security team to use historical information to protect against the second attack?
Options
- AKey risk indicators
- BLessons learned
- CRecovery point objectives
- DTabletop exercise
How the community answered
(37 responses)- A5% (2)
- B92% (34)
- C3% (1)
Why each option
A lessons learned process formally documents findings from past incidents and applies them to improve defenses, which would have allowed the team to address the repeated vulnerability before the second attack.
Key risk indicators are metrics used to monitor ongoing risk levels and do not capture or apply historical incident-specific vulnerability details.
Lessons learned is a structured post-incident review that captures technical details including exploited vulnerabilities, remediation actions taken, and process gaps. Had the team documented and acted on findings from the first compromise - specifically the vulnerability used - they would have had historical context to detect or block the same attack vector on different systems during the second incident.
Recovery point objectives define acceptable data loss thresholds for backup and recovery planning and are unrelated to preventing repeated exploitation of a known vulnerability.
Tabletop exercises simulate hypothetical scenarios for training purposes but do not produce or apply historical vulnerability remediation records.
Concept tested: Applying lessons learned to prevent repeated incidents
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.