nerdexam
CompTIA

CAS-003 · Question #826

Following a major security incident that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root-cause…

The correct answer is A. Capture recommendations from a lessons-learned session with key management. After a major incident, a CISO must translate root-cause findings into actionable improvements, which requires a structured lessons-learned session with stakeholders who can drive change.

Enterprise Security Operations

Question

Following a major security incident that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root-cause analysis. Which of the following additional steps should the CISO take to mitigate the chance of a recurrence?

Options

  • ACapture recommendations from a lessons-learned session with key management.
  • BInstall additional detective controls to facilitate a better root cause analysis in future incidents.
  • CPurchase cyber-incident insurance, specifically covering the root cause.
  • DCompile a report containing all help desk tickets received during the incident.

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    17% (6)
  • C
    9% (3)
  • D
    3% (1)

Why each option

After a major incident, a CISO must translate root-cause findings into actionable improvements, which requires a structured lessons-learned session with stakeholders who can drive change.

ACapture recommendations from a lessons-learned session with key management.Correct

A lessons-learned session with key management captures institutional knowledge about what failed, why it failed, and what controls must be added or changed. This directly converts root-cause findings into formal recommendations that leadership can fund and prioritize, closing the gap that allowed the incident to occur.

BInstall additional detective controls to facilitate a better root cause analysis in future incidents.

Installing additional detective controls improves future detection but does not address the root cause or prevent the same incident from recurring - it only helps identify the next one faster.

CPurchase cyber-incident insurance, specifically covering the root cause.

Cyber-incident insurance transfers financial risk but does nothing to reduce the likelihood or severity of a recurrence; it is a risk transfer mechanism, not a risk mitigation strategy.

DCompile a report containing all help desk tickets received during the incident.

Compiling help desk tickets is a data-gathering activity that may support analysis, but it does not constitute a step toward preventing recurrence and lacks the actionable output of a lessons-learned session.

Concept tested: Post-incident lessons-learned process for risk reduction

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#lessons learned#root cause analysis#post-incident review

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice