nerdexam
GIAC

GCIH · Question #623

An incident handler concluded that a recent breach could have been prevented with a software patch. In their report they recommended the organization perform regular vulnerability scans, document…

The correct answer is C. Following up on post-incident recommendations. The organization failed to act on explicit post-incident recommendations to patch software, allowing the same class of vulnerability to cause a second breach six months later.

Incident Response & Cyber Kill Chain

Question

An incident handler concluded that a recent breach could have been prevented with a software patch. In their report they recommended the organization perform regular vulnerability scans, document the findings and update software assets. Six months later the incident handler investigates a new breach and concludes the web server was infected due to an outdated version of a Content Management System (CMS). Based on this information, what part of the incident handling process does the organization need to improve?

Options

  • ADisabling unused software to prevent infection
  • BIdentifying and responding to incidents quickly
  • CFollowing up on post-incident recommendations
  • DMaintaining time-stamped logs of user activity

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    14% (3)
  • C
    77% (17)
  • D
    5% (1)

Why each option

The organization failed to act on explicit post-incident recommendations to patch software, allowing the same class of vulnerability to cause a second breach six months later.

ADisabling unused software to prevent infection

Disabling unused software was not part of the recommendations made after the first incident, so it does not represent the gap the scenario is illustrating.

BIdentifying and responding to incidents quickly

The question focuses on a preventable recurrence caused by known, unpatched vulnerabilities, not on the speed of detection or containment during either incident.

CFollowing up on post-incident recommendationsCorrect

After the first incident, the handler documented specific remediation steps including regular vulnerability scanning and software updates. The second breach - caused by an unpatched CMS - demonstrates those recommendations were never implemented. Failing to close the loop on post-incident action items is a breakdown in the lessons-learned and follow-up phase of the incident handling lifecycle.

DMaintaining time-stamped logs of user activity

Maintaining time-stamped logs addresses evidence collection and forensic auditing, not the remediation gap that allowed the same class of vulnerability to persist unpatched.

Concept tested: Incident handling lessons learned and follow-up phase

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#post-incident review#patch management#lessons learned#incident handling lifecycle

Community Discussion

No community discussion yet for this question.

Full GCIH Practice