CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A cyber incident response team has successfully contained a sophisticated persistent threat (APT) from their network. They are now in the post-incident activity phase. Which of the following activities is MOST crucial for improving the organization's future security posture based on this incident?
- AUpdate the incident response plan to reflect new procedures.
- BArchive all incident logs and forensic images for future reference.
- CTrain all employees on advanced phishing detection techniques.
- DConduct a lessons learned meeting with all involved stakeholders.
Show answer & explanationAnswer & explanation
Correct answer: D. Conduct a lessons learned meeting with all involved stakeholders.
A 'lessons learned' meeting is the most crucial activity as it facilitates a comprehensive review of the entire incident, identifies what worked and what didn't, and gathers insights from all stakeholders to drive actionable improvements across processes, technologies, and training.
Why the other options are wrong
- A. Updating the IR plan is an outcome of the lessons learned meeting, not the meeting itself.
- B. Archiving evidence is important for compliance and potential legal action, but it doesn't directly lead to process improvement.
- C. Training employees is a potential recommendation stemming from a lessons learned review, but the meeting is the foundational step for identifying such needs.
Post-Incident Activity
The final phase of incident response focused on improving security posture and response capabilities based on lessons learned from an incident.
- Includes lessons learned meetings.
- Updates incident response plans.
- Aims for continuous improvement.
Memory trick: After the storm, we 'Review' the damage and 'Improve' our defenses.