GCIH · Question #769
Which activity helps readdress security tasks identified in past incident reports?
The correct answer is C. Follow-up review meetings. Follow-up review meetings are specifically designed to revisit and track unresolved or newly identified security tasks from prior incident reports, ensuring remediation actions are completed.
Question
Which activity helps readdress security tasks identified in past incident reports?
Options
- AAfter Action Report
- BRoot cause analysis
- CFollow-up review meetings
- DContainment and eradication
How the community answered
(30 responses)- B3% (1)
- C90% (27)
- D7% (2)
Why each option
Follow-up review meetings are specifically designed to revisit and track unresolved or newly identified security tasks from prior incident reports, ensuring remediation actions are completed.
An After Action Report documents the timeline, impact, and lessons learned from a specific incident; it identifies tasks but does not itself re-examine or track progress on tasks from previous reports.
Root cause analysis determines the underlying technical or process failure that enabled an incident; it is performed during or immediately after an incident, not as an ongoing review of past report tasks.
Follow-up review meetings provide a structured forum to revisit the action items, remediations, and security gaps documented in past incident reports, assigning ownership and verifying completion. This activity closes the loop on previously identified vulnerabilities and process failures, which is a core component of the post-incident activity phase defined in NIST SP 800-61. Without these meetings, tasks identified in reports often go unaddressed.
Containment and eradication are active incident response phases focused on stopping an ongoing threat and removing it, not reviewing historical reports or managing outstanding remediation tasks.
Concept tested: Post-incident follow-up and remediation tracking
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.