CS0-003 · Question #419
Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the…
The correct answer is B. Lessons learned. The lessons learned process is the final stage of the incident management life cycle, where the incident team reviews the incident and evaluates the effectiveness of the response and the plans in place. The lessons learned report should include the who-what-when information and…
Question
Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the effectiveness of the plans in place. Which of the following incident management life cycle processes does this describe?
Options
- ABusiness continuity plan
- BLessons learned
- CForensic analysis
- DIncident response plan
How the community answered
(16 responses)- A6% (1)
- B69% (11)
- C6% (1)
- D19% (3)
Explanation
The lessons learned process is the final stage of the incident management life cycle, where the incident team reviews the incident and evaluates the effectiveness of the response and the plans in place. The lessons learned report should include the who-what-when information and any recommendations for improvement.
Topics
Community Discussion
No community discussion yet for this question.