nerdexam
CompTIA

CS0-003 · Question #263

Which of the following best describes the actions taken by an organization after the resolution of an incident that addresses issues and reflects on the growth opportunities for future incidents?

The correct answer is A. Lessons learned. The question asks to identify the term describing an organization's post-incident actions focused on addressing issues and identifying growth opportunities for future incidents.

Submitted by satoshi_tk· Mar 6, 2026Incident Response and Management

Question

Which of the following best describes the actions taken by an organization after the resolution of an incident that addresses issues and reflects on the growth opportunities for future incidents?

Options

  • ALessons learned
  • BScrum review
  • CRoot cause analysis
  • DRegulatory compliance

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    7% (2)
  • D
    3% (1)

Why each option

The question asks to identify the term describing an organization's post-incident actions focused on addressing issues and identifying growth opportunities for future incidents.

ALessons learnedCorrect

Lessons learned is a formal process conducted after an incident has been resolved, where the incident response team reviews what occurred, identifies successes and failures, and determines actionable improvements for future incident handling and prevention. This directly covers reflection on growth opportunities and addressing systemic issues.

BScrum review

A Scrum review is a meeting in Agile software development to inspect the increment and adapt the backlog, unrelated to incident response.

CRoot cause analysis

Root cause analysis (RCA) is a component of the post-incident process that focuses specifically on identifying the underlying reasons for an incident, but 'lessons learned' is a broader phase encompassing RCA along with process improvements and training.

DRegulatory compliance

Regulatory compliance refers to adherence to laws and regulations; while an incident might have compliance implications, it does not describe the post-resolution reflection process itself.

Concept tested: Incident response post-mortem (lessons learned)

Source: https://learn.microsoft.com/en-us/compliance/regulatory/incident-response-playbook-analyze-recover

Topics

#Lessons learned#Incident post-mortem#Incident response process

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice