SY0-701 · Question #12
Which of the following describes the reason root cause analysis should be conducted as part of incident response?
The correct answer is D. To prevent future incidents of the same nature. Root cause analysis is a process of identifying and resolving the underlying factors that led to an incident. By conducting root cause analysis as part of incident response, security professionals can learn from the incident and implement corrective actions to prevent future…
Question
Which of the following describes the reason root cause analysis should be conducted as part of incident response?
Options
- ATo gather loCs for the investigation
- BTo discover which systems have been affected
- CTo eradicate any trace of malware on the network
- DTo prevent future incidents of the same nature
How the community answered
(28 responses)- B4% (1)
- D96% (27)
Explanation
Root cause analysis is a process of identifying and resolving the underlying factors that led to an incident. By conducting root cause analysis as part of incident response, security professionals can learn from the incident and implement corrective actions to prevent future incidents of the same nature. For example, if the root cause of a data breach was a weak password policy, the security team can enforce a stronger password policy and educate users on the importance of password security. Root cause analysis can also help to improve security processes, policies, and procedures, and to enhance security awareness and culture within the organization. Root cause analysis is not meant to gather loCs (indicators of compromise) for the investigation, as this is a task performed during the identification and analysis phases of incident response. Root cause analysis is also not meant to discover which systems have been affected or to eradicate any trace of malware on the network, as these are tasks performed during the containment and eradication phases of incident response.
Community Discussion
No community discussion yet for this question.