nerdexam
CompTIA

CS0-003 · Question #419

Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the…

The correct answer is B. Lessons learned. The lessons learned process is the final stage of the incident management life cycle, where the incident team reviews the incident and evaluates the effectiveness of the response and the plans in place. The lessons learned report should include the who-what-when information and…

Submitted by akirajp· Mar 6, 2026Incident Response and Management

Question

Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the effectiveness of the plans in place. Which of the following incident management life cycle processes does this describe?

Options

  • ABusiness continuity plan
  • BLessons learned
  • CForensic analysis
  • DIncident response plan

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    69% (11)
  • C
    6% (1)
  • D
    19% (3)

Explanation

The lessons learned process is the final stage of the incident management life cycle, where the incident team reviews the incident and evaluates the effectiveness of the response and the plans in place. The lessons learned report should include the who-what-when information and any recommendations for improvement.

Topics

#Lessons learned#Incident reporting#Incident response lifecycle#Post-incident review

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice