SY0-501 · Question #393
Following the successful response to a data-leakage incident, the incident team lead facilitates an exercise that focuses on continuous improvement of the organization's incident response…
The correct answer is A. Lessons learned review. The incident team lead is facilitating a structured review following a data leakage incident, with the specific aim of enhancing the organization's incident response capabilities through continuous improvement.
Question
Following the successful response to a data-leakage incident, the incident team lead facilitates an exercise that focuses on continuous improvement of the organization's incident response capabilities. Which of the following activities has the incident team lead executed?
Options
- ALessons learned review
- BRoot cause analysis
- CIncident audit
- DCorrective action exercise
How the community answered
(65 responses)- A82% (53)
- B11% (7)
- C3% (2)
- D5% (3)
Why each option
The incident team lead is facilitating a structured review following a data leakage incident, with the specific aim of enhancing the organization's incident response capabilities through continuous improvement.
A lessons learned review is a systematic process conducted after an incident to evaluate the effectiveness of the incident response, identify successes and failures, and derive actionable insights for continuous improvement of processes and capabilities. This activity directly aligns with the goal of improving incident response capabilities post-incident.
Root cause analysis focuses on identifying the fundamental underlying reasons for an incident, which is a component of a larger review but not the overarching exercise aimed at improving overall incident response capabilities.
An incident audit is a formal, independent examination of incident response processes and compliance, which differs from a team-led exercise specifically focused on internal continuous operational improvement.
A corrective action exercise involves the implementation or practice of specific remediation steps; however, it does not encompass the broader review and identification of areas for continuous improvement of capabilities that precede such actions.
Concept tested: Post-incident review and continuous improvement
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/incident-response-plan-best-practices#review-and-update-the-plan
Topics
Community Discussion
No community discussion yet for this question.