CAS-003 · Question #930
A security analyst must carry out the incident response plan for a specific targeted attack that was detected by the security operations center. The director of network security wants to ensure this…
The correct answer is B. Root cause analysis. The director's explicit goal is to prevent the attack from happening again. Root cause analysis (RCA) is the correct answer because it systematically identifies the underlying vulnerabilities, misconfigurations, or weaknesses that allowed the attack to succeed in the first…
Question
A security analyst must carry out the incident response plan for a specific targeted attack that was detected by the security operations center. The director of network security wants to ensure this type of attack cannot be executed again in the environment. Which of the following should the analyst present to the director to BEST meet the director's goal?
Options
- AIncident downtime statistics
- BRoot cause analysis
- CAfter-action report
- DIncident scope and cost metrics
How the community answered
(39 responses)- A3% (1)
- B90% (35)
- C3% (1)
- D5% (2)
Explanation
The director's explicit goal is to prevent the attack from happening again. Root cause analysis (RCA) is the correct answer because it systematically identifies the underlying vulnerabilities, misconfigurations, or weaknesses that allowed the attack to succeed in the first place. Without knowing the root cause, you cannot reliably prevent recurrence. Incident downtime statistics (A) and incident scope/cost metrics (D) are useful for business impact reporting but do not address the 'why it happened' question needed for prevention. An after-action report (C) documents what occurred and lessons learned at a high level, but RCA is the specific deep-dive analysis that exposes the technical and procedural root causes that must be remediated.
Topics
Community Discussion
No community discussion yet for this question.