nerdexam
CompTIA

SY0-501 · Question #164

During a data breach cleanup it is discovered that not all of the sites involved have the necessary data wiping tools. The necessary tools are quickly distributed to the required technicians, but…

The correct answer is D. Lessons Learned. The question asks for the best time to revisit a critical process failure, specifically the lack of necessary data wiping tools discovered during a data breach cleanup. The appropriate phase for this type of review and improvement planning is Lessons Learned.

Submitted by tom_us· Mar 4, 2026Security operations

Question

During a data breach cleanup it is discovered that not all of the sites involved have the necessary data wiping tools. The necessary tools are quickly distributed to the required technicians, but when should this problem BEST be revisited?

Options

  • AReporting
  • BPreparation
  • CMitigation
  • DLessons Learned

How the community answered

(43 responses)
  • A
    14% (6)
  • B
    5% (2)
  • C
    7% (3)
  • D
    74% (32)

Why each option

The question asks for the best time to revisit a critical process failure, specifically the lack of necessary data wiping tools discovered during a data breach cleanup. The appropriate phase for this type of review and improvement planning is Lessons Learned.

AReporting

Reporting focuses on documenting the incident details and the response actions for stakeholders, rather than systematically analyzing process failures for long-term improvement.

BPreparation

Preparation is the phase before an incident, involving proactive planning and resource allocation; while the problem relates to preparation, revisiting and fixing the discovered flaw happens after the incident response.

CMitigation

Mitigation involves immediate actions to contain and eradicate the threat during an active incident, and it is not the phase for post-incident analysis of process shortcomings.

DLessons LearnedCorrect

The Lessons Learned phase, which occurs after an incident has been contained and resolved, is specifically dedicated to analyzing the entire incident response process. Its purpose is to identify deficiencies, understand what worked well and what didn't, and develop actionable plans to improve future incident responses, making it the ideal time to address the discovered lack of data wiping tools to prevent recurrence.

Concept tested: Incident Response Life Cycle - Lessons Learned

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/incident-response-plan-overview?view=o365-worldwide

Topics

#incident response#lessons learned#data breach#IR lifecycle

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice