200-201 Question 354
Select 4After a recent cybersecurity incident in which an organization's sensitive data was leaked, the incident response (IR) team conducts a post-incident analysis. Which of the following actions should be prioritized during the lessons learned phase to improve the organization's security posture?
- A
Identify gaps in the incident response plan (IRP) and recommend updates.
- B
Analyze the attack vector and methods used by the threat actor.
- C
Destroy all logs and evidence collected during the incident to avoid legal liability.
- D
Develop and implement additional training for employees based on incident findings.
- E
Discuss non-technical outcomes such as financial or reputational impact with stakeholders.
Show answer and explanation
Correct answers: A, B, D, E
Explanation
The lessons learned phase of post-incident analysis focuses on improving the organization's overall security posture by addressing gaps in the incident response plan, understanding the root cause of the incident, and implementing measures to prevent similar incidents. It also involves sharing the results with stakeholders to ensure a comprehensive understanding of the incident's impact. Destroying logs and evidence is not an appropriate action as it hinders accountability and compliance efforts.
- A. Correct.
Identifying gaps in the incident response plan is a critical part of the lessons learned phase. This ensures the organization can improve its response to similar incidents in the future.
- B. Correct.
Analyzing the attack vector and methods used helps determine how the incident occurred, enabling the organization to address any vulnerabilities and prevent recurrence.
- C. Incorrect.
Destroying logs and evidence is not a recommended practice. Evidence must be preserved for legal, compliance, and forensic purposes.
- D. Correct.
Developing and implementing additional training ensures that employees are better prepared to recognize and respond to similar threats in the future, reducing the likelihood of future incidents.
- E. Correct.
Discussing non-technical outcomes such as financial or reputational impact ensures stakeholders understand the broader implications of the incident and can make informed decisions moving forward.