CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy

A security analyst is compiling a 'lessons learned' report after a successful phishing campaign resulted in a minor data breach. The report needs to identify areas for improvement in both technical controls and organizational processes. Which section of the report should detail the specific actions that will be taken to prevent recurrence and strengthen defenses?

  1. ARecommendations and Action Plan
  2. BImpact Assessment
  3. CIncident Timeline
  4. DExecutive Summary
Show answer & explanation

Correct answer: A. Recommendations and Action Plan

The 'Recommendations and Action Plan' section is specifically designed to outline proposed solutions, concrete steps, assigned responsibilities, and timelines for addressing the deficiencies identified during the incident review.

Why the other options are wrong

  • B. The impact assessment describes the consequences of the incident, not the corrective actions.
  • C. The incident timeline details the sequence of events, not future actions.
  • D. The executive summary provides a high-level overview, not specific actions.

Lessons Learned Report

A document created after an incident to analyze what happened, why it happened, and what can be done to improve future incident response and prevention.

  • Focuses on continuous improvement.
  • Includes incident overview, analysis, and recommendations.
  • Aims to prevent recurrence and strengthen security posture.

Memory trick: Report's plan is where the 'do' list lives.

More Reporting and Communication questions