nerdexam
CompTIA

SY0-301 · Question #396

After a recent security breach, the network administrator has been tasked to update and backup all router and switch configurations. The security administrator has been tasked to enforce stricter…

The correct answer is D. Lessons learned. Conducting post-incident reviews to update configurations, enforce stricter policies, and provide additional training are all hallmarks of a 'lessons learned' risk mitigation strategy. This approach uses the breach as a learning opportunity to strengthen future defenses.

Security operations

Question

After a recent security breach, the network administrator has been tasked to update and backup all router and switch configurations. The security administrator has been tasked to enforce stricter security policies. All users were forced to undergo additional user awareness training. All of these actions are due to which of the following types of risk mitigation strategies?

Options

  • AChange management
  • BImplementing policies to prevent data loss
  • CUser rights and permissions review
  • DLessons learned

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    3% (1)
  • D
    89% (32)

Why each option

Conducting post-incident reviews to update configurations, enforce stricter policies, and provide additional training are all hallmarks of a 'lessons learned' risk mitigation strategy. This approach uses the breach as a learning opportunity to strengthen future defenses.

AChange management

Change management governs how changes are approved and implemented before they occur, not a reactive process triggered by a breach.

BImplementing policies to prevent data loss

Implementing data loss prevention policies is one specific control type, not the overarching strategy that encompasses configuration updates and training together.

CUser rights and permissions review

A user rights and permissions review is a specific audit activity and does not describe the full scope of the post-breach improvements mentioned.

DLessons learnedCorrect

Lessons learned is a post-incident risk mitigation strategy where an organization reviews what happened during a security event and uses those findings to drive improvements across people, processes, and technology. The described actions - updating configurations, enforcing stricter policies, and requiring awareness training - are all direct outcomes of a lessons learned process following the breach.

Concept tested: Post-incident lessons learned risk mitigation strategy

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#lessons learned#incident response#post-incident review#risk mitigation

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice