nerdexam
CompTIA

SY0-501 · Question #387

Legal authorities notify a company that its network has been compromised for the second time in two years. The investigation shows the attackers were able to use the same vulnerability on different…

The correct answer is B. Lessons learned. Lessons Learned (B) is correct because it is the formal process of documenting what went wrong after an incident - including vulnerabilities exploited, gaps in controls, and recommended remediations. Had the team properly conducted and acted on a lessons learned review after…

Submitted by chiamaka_o· Mar 4, 2026Security program management and oversight

Question

Legal authorities notify a company that its network has been compromised for the second time in two years. The investigation shows the attackers were able to use the same vulnerability on different systems in both attacks. Which of the following would have allowed the security team to use historical information to protect against the second attack?

Options

  • AKey risk indicators
  • BLessons learned
  • CRecovery point objectives
  • DTabletop exercise

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    73% (24)
  • C
    15% (5)
  • D
    9% (3)

Explanation

Lessons Learned (B) is correct because it is the formal process of documenting what went wrong after an incident - including vulnerabilities exploited, gaps in controls, and recommended remediations. Had the team properly conducted and acted on a lessons learned review after the first attack, they would have identified and patched the vulnerability before attackers reused it on different systems.

  • A (Key Risk Indicators) are metrics used to monitor ongoing risk levels in real time - they signal when risk is rising, but they don't capture historical incident details or remediation steps.
  • C (Recovery Point Objectives) define how much data loss is acceptable during recovery (a backup/DR concept) - entirely unrelated to analyzing past attack vectors.
  • D (Tabletop Exercise) is a simulated discussion-based drill used to test response plans; it's a proactive planning tool, not a mechanism for applying historical incident knowledge.

Memory tip: Think of "Lessons Learned" as your incident post-mortem report - it's the paper trail that answers "what happened and how do we stop it from happening again?" If the team filed it and acted on it, the second breach would never have happened.

Topics

#Lessons learned#Incident response#Vulnerability management#Continuous improvement

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice