200-201 Question 342
Select 3After a ransomware attack on a company's network was mitigated, the cybersecurity team conducted a post-incident analysis. Which actions are most appropriate during the lessons learned phase to improve future incident response processes?
- A
Identify gaps in the incident response plan and implement necessary updates.
- B
Determine the root cause of the incident to prevent future occurrences.
- C
Revert all system changes made during the containment phase to return to the original state.
- D
Review the effectiveness of communication during the incident and make necessary improvements.
- E
Destroy all evidence related to the incident to prevent legal complications.
Show answer and explanation
Correct answers: A, B, D
Explanation
The lessons learned phase of post-incident analysis involves evaluating what went well, what failed, and what could be improved in the incident response process. This includes updating plans, addressing root causes, and refining communication processes to ensure the organization is better prepared for future incidents. Actions like reverting critical changes or destroying evidence are counterproductive and can hinder future preparation or legal proceedings.
- A. Correct.
Identifying gaps in the incident response plan and implementing updates is a critical step in the lessons learned phase to enhance future preparedness.
- B. Correct.
Determining the root cause is essential to ensure the organization addresses vulnerabilities and minimizes the likelihood of a similar attack.
- C. Incorrect.
Reverting all system changes made during containment is not appropriate, as some changes may have been deliberate to enhance security or resolve vulnerabilities.
- D. Correct.
Reviewing communication processes ensures that any delays or misunderstandings during the incident are identified and resolved for future incidents.
- E. Incorrect.
Destroying evidence is not an appropriate action as it is critical for forensic analysis, legal compliance, and learning from the incident.