300-215 Question 9
Select 3During an investigation into a ransomware attack on a corporate network, you are tasked with creating a root cause analysis (RCA) report. Which components should be included to ensure a comprehensive RCA report?
- A
Timeline of events leading up to the incident
- B
List of firewalls deployed across the network
- C
Root cause of the incident with supporting evidence
- D
Remediation steps taken and recommended preventive measures
- E
Names of team members involved in the response
Show answer and explanation
Correct answers: A, C, D
Explanation
A comprehensive root cause analysis (RCA) report should focus on providing actionable insights into what caused the incident, how it unfolded, and how to prevent it in the future. Key components include a detailed timeline, the root cause with evidence, and remediation and prevention strategies. Extraneous details, such as the names of team members or generic network architecture information, do not contribute meaningfully to the RCA.
- A. Correct.
A timeline of events is crucial for understanding the sequence of actions that led to the incident and helps identify gaps in detection or response.
- B. Incorrect.
While the network's firewall details may be useful in other contexts, they are not a required component of an RCA report unless they directly contribute to the root cause.
- C. Correct.
The root cause and supporting evidence are the cornerstone of any RCA report, as they identify the fundamental issue and justify the findings.
- D. Correct.
Remediation steps and recommended preventive measures are essential to ensure the organization learns from the incident and prevents recurrence.
- E. Incorrect.
Including the names of team members involved in the response is unnecessary for an RCA report and may violate privacy policies.