SY0-301 · Question #396
After a recent security breach, the network administrator has been tasked to update and backup all router and switch configurations. The security administrator has been tasked to enforce stricter…
The correct answer is D. Lessons learned. Conducting post-incident reviews to update configurations, enforce stricter policies, and provide additional training are all hallmarks of a 'lessons learned' risk mitigation strategy. This approach uses the breach as a learning opportunity to strengthen future defenses.
Question
After a recent security breach, the network administrator has been tasked to update and backup all router and switch configurations. The security administrator has been tasked to enforce stricter security policies. All users were forced to undergo additional user awareness training. All of these actions are due to which of the following types of risk mitigation strategies?
Options
- AChange management
- BImplementing policies to prevent data loss
- CUser rights and permissions review
- DLessons learned
How the community answered
(36 responses)- A3% (1)
- B6% (2)
- C3% (1)
- D89% (32)
Why each option
Conducting post-incident reviews to update configurations, enforce stricter policies, and provide additional training are all hallmarks of a 'lessons learned' risk mitigation strategy. This approach uses the breach as a learning opportunity to strengthen future defenses.
Change management governs how changes are approved and implemented before they occur, not a reactive process triggered by a breach.
Implementing data loss prevention policies is one specific control type, not the overarching strategy that encompasses configuration updates and training together.
A user rights and permissions review is a specific audit activity and does not describe the full scope of the post-breach improvements mentioned.
Lessons learned is a post-incident risk mitigation strategy where an organization reviews what happened during a security event and uses those findings to drive improvements across people, processes, and technology. The described actions - updating configurations, enforcing stricter policies, and requiring awareness training - are all direct outcomes of a lessons learned process following the breach.
Concept tested: Post-incident lessons learned risk mitigation strategy
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.