nerdexam
GIAC

GCIH · Question #769

Which activity helps readdress security tasks identified in past incident reports?

The correct answer is C. Follow-up review meetings. Follow-up review meetings are specifically designed to revisit and track unresolved or newly identified security tasks from prior incident reports, ensuring remediation actions are completed.

Incident Response & Cyber Kill Chain

Question

Which activity helps readdress security tasks identified in past incident reports?

Options

  • AAfter Action Report
  • BRoot cause analysis
  • CFollow-up review meetings
  • DContainment and eradication

How the community answered

(30 responses)
  • B
    3% (1)
  • C
    90% (27)
  • D
    7% (2)

Why each option

Follow-up review meetings are specifically designed to revisit and track unresolved or newly identified security tasks from prior incident reports, ensuring remediation actions are completed.

AAfter Action Report

An After Action Report documents the timeline, impact, and lessons learned from a specific incident; it identifies tasks but does not itself re-examine or track progress on tasks from previous reports.

BRoot cause analysis

Root cause analysis determines the underlying technical or process failure that enabled an incident; it is performed during or immediately after an incident, not as an ongoing review of past report tasks.

CFollow-up review meetingsCorrect

Follow-up review meetings provide a structured forum to revisit the action items, remediations, and security gaps documented in past incident reports, assigning ownership and verifying completion. This activity closes the loop on previously identified vulnerabilities and process failures, which is a core component of the post-incident activity phase defined in NIST SP 800-61. Without these meetings, tasks identified in reports often go unaddressed.

DContainment and eradication

Containment and eradication are active incident response phases focused on stopping an ongoing threat and removing it, not reviewing historical reports or managing outstanding remediation tasks.

Concept tested: Post-incident follow-up and remediation tracking

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#follow-up review#after action#security tasks#incident reporting

Community Discussion

No community discussion yet for this question.

Full GCIH Practice