CompTIA Security+ (SY0-701)Security OperationsMedium

After restoring services from a widespread outage caused by a misconfigured firewall rule, the incident response team wants to determine the underlying reason the misconfiguration was deployed without review. Which activity should the team perform?

  1. ACVSS rescoring
  2. BRoot cause analysis
  3. CChain of custody documentation
  4. DOrder of volatility assessment
Show answer & explanation

Correct answer: B. Root cause analysis

Root cause analysis systematically investigates why an incident occurred, tracing back to the underlying process failure, such as a bypassed change management review, so preventive measures can be implemented.

Why the other options are wrong

  • A. CVSS rescoring re-evaluates vulnerability severity, not process failure causes.
  • C. Chain of custody applies to evidence handling in forensic investigations, not process failures.
  • D. Order of volatility governs the sequence of evidence collection, unrelated to root cause.

Root Cause Analysis

A structured investigation technique used after an incident to identify the fundamental underlying cause, not just the symptoms, to prevent recurrence.

  • Often performed during the lessons-learned phase of incident response
  • Techniques include the '5 Whys' and fishbone diagrams
  • Leads to corrective actions like updated change management controls

Memory trick: Dig past the branches to find the root that caused the tree to fall.

More Security Operations questions