200-201 Question 341
Select 3After a ransomware attack on an organization, the incident response team conducts a post-incident analysis. Which of the following actions should be included in the lessons learned phase?
- A
Identify gaps in the incident response plan and recommend updates.
- B
Determine the root cause of the incident and document findings.
- C
Delete all logs from the incident to free up storage space.
- D
Conduct training sessions to address gaps identified during the incident.
- E
Share incident details publicly without management approval.
Show answer and explanation
Correct answers: A, B, D
Explanation
The lessons learned phase of post-incident analysis aims to improve an organization's ability to detect, respond to, and recover from future incidents. This includes identifying and addressing gaps in processes, determining the root cause, and providing training to mitigate identified weaknesses. Actions such as deleting logs or sharing information without approval are not aligned with best practices in cybersecurity operations.
- A. Correct.
Updating the incident response plan based on identified gaps is a critical component of the lessons learned phase to improve future responses.
- B. Correct.
Determining and documenting the root cause ensures that the organization understands how the incident occurred and can prevent similar events.
- C. Incorrect.
Deleting logs would prevent further analysis and evaluation of the incident, which is counterproductive to the lessons learned process.
- D. Correct.
Training sessions help address knowledge or skill gaps identified during the incident, strengthening the team's future readiness.
- E. Incorrect.
Sharing incident details publicly without management approval could lead to reputational damage and legal issues, making it an inappropriate action.