nerdexam
CompTIA

CAS-003 · Question #901

Following a major security modem that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root cause…

The correct answer is A. Capture recommendations from a lessons-learned session with key management. After completing a root cause analysis, the next logical step in the post-incident process is a lessons-learned session. This session, attended by key stakeholders and management, transforms root cause findings into actionable recommendations - procedural changes, control…

Enterprise Security Operations

Question

Following a major security modem that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a root cause analysis. Which of the following additional steps should the CISO take to mitigate the chance of a recurrence?

Options

  • ACapture recommendations from a lessons-learned session with key management
  • BInstall additional detective controls to facilitate a better root cause analysts in future incidents
  • CPurchase cyber-incident insurance specifically covering the root cause
  • DCompile a report containing all help desk tickets received during the incident

How the community answered

(60 responses)
  • A
    78% (47)
  • B
    12% (7)
  • C
    3% (2)
  • D
    7% (4)

Explanation

After completing a root cause analysis, the next logical step in the post-incident process is a lessons-learned session. This session, attended by key stakeholders and management, transforms root cause findings into actionable recommendations - procedural changes, control improvements, training updates - that directly reduce recurrence risk. Option B (more detective controls) improves future detection but doesn't prevent the same root cause from recurring. Option C (cyber insurance) covers financial losses after an incident but provides no preventive value. Option D (compiling help desk tickets) is purely historical documentation and produces no actionable mitigations. The lessons-learned process is a cornerstone of incident response maturity frameworks such as NIST SP 800-61.

Topics

#incident response#lessons learned#root cause analysis#CISO

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice