350-201 Question 168
Single answerYou are a security analyst for a mid-sized organization. During a routine review of your incident response process, you notice that after incidents are resolved, no follow-up actions are performed to analyze the root cause or improve future responses. Which process should you integrate into your incident response lifecycle to address this gap?
- A
Preparation
- B
Detection and Analysis
- C
Containment, Eradication, and Recovery
- D
Post-Incident Activity
Show answer and explanation
Correct answer: D
Explanation
Post-Incident Activity is a critical process in the incident response lifecycle that ensures organizations learn from past incidents. By analyzing the root cause, documenting lessons learned, and updating response plans, organizations can improve their preparedness and response to future incidents, addressing the identified gap in the scenario.
- A. Incorrect.
Preparation focuses on establishing the necessary tools, policies, and procedures to handle incidents effectively but does not address post-incident follow-up or improvements.
- B. Incorrect.
Detection and Analysis involve identifying potential security incidents and evaluating their severity but do not deal with post-resolution activities.
- C. Incorrect.
Containment, Eradication, and Recovery aim to limit the spread of an incident, remove the threat, and restore normal operations but do not include follow-up analysis or process refinement.
- D. Correct.
Post-Incident Activity includes analyzing the root cause of incidents, documenting lessons learned, and implementing improvements to strengthen future responses, making it the correct answer.