CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is conducting a post-incident review for a ransomware attack that encrypted several departmental file shares. The 'lessons learned' report needs to include a section on 'Analysis of Contributing Factors' to understand why the attack was successful. Which of the following categories of information would be MOST critical to include in this section?

  1. ADetailed chronological log of all recovery steps taken.
  2. BIdentification of initial compromise vector, unpatched systems, and insufficient user training.
  3. CTotal financial cost of the incident to the organization.
  4. DList of all individuals involved in the incident response team.
Show answer & explanation

Correct answer: B. Identification of initial compromise vector, unpatched systems, and insufficient user training.

The 'Analysis of Contributing Factors' aims to identify the root causes and weaknesses that enabled the incident. Identifying the initial compromise vector (how it got in), unpatched systems (vulnerabilities exploited), and insufficient user training (human factor) directly addresses 'why' the attack was successful.

Why the other options are wrong

  • A. Recovery steps belong in the 'Recovery' or 'Incident Timeline' section, not contributing factors.
  • C. Financial cost is part of impact assessment, not contributing factors.
  • D. The list of IR team members is administrative information, not a contributing factor to the attack's success.

Analysis of Contributing Factors

A component of a post-incident review that investigates the underlying conditions, weaknesses, or vulnerabilities that allowed an incident to occur or escalate.

  • Identifies root causes, not just symptoms.
  • Covers technical, procedural, and human elements.
  • Informs future preventative measures.

Memory trick: Why did it happen? Find the vector, patch holes, and train people.

More Reporting and Communication questions