CompTIA Security+ (SY0-701)Security OperationsMedium
After restoring services from a widespread outage caused by a misconfigured firewall rule, the incident response team wants to determine the underlying reason the misconfiguration was deployed without review. Which activity should the team perform?
- ACVSS rescoring
- BRoot cause analysis
- CChain of custody documentation
- DOrder of volatility assessment
Show answer & explanationAnswer & explanation
Correct answer: B. Root cause analysis
Root cause analysis systematically investigates why an incident occurred, tracing back to the underlying process failure, such as a bypassed change management review, so preventive measures can be implemented.
Why the other options are wrong
- A. CVSS rescoring re-evaluates vulnerability severity, not process failure causes.
- C. Chain of custody applies to evidence handling in forensic investigations, not process failures.
- D. Order of volatility governs the sequence of evidence collection, unrelated to root cause.
Root Cause Analysis
A structured investigation technique used after an incident to identify the fundamental underlying cause, not just the symptoms, to prevent recurrence.
- Often performed during the lessons-learned phase of incident response
- Techniques include the '5 Whys' and fishbone diagrams
- Leads to corrective actions like updated change management controls
Memory trick: Dig past the branches to find the root that caused the tree to fall.