CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst is conducting a post-incident review for a successful phishing attack that led to credential compromise. During the 'lessons learned' meeting, the team identifies that the primary control failure was the lack of multi-factor authentication (MFA) on the affected email accounts. Which section of the 'lessons learned' report should detail this specific control gap and its impact?
- AIncident Summary
- BTimeline of Events
- CRecommendations for Improvement
- DRoot Cause Analysis
Show answer & explanationAnswer & explanation
Correct answer: D. Root Cause Analysis
The Root Cause Analysis section of a 'lessons learned' report is specifically designed to identify the underlying reasons for an incident, including control failures like the lack of MFA, which directly contributed to the credential compromise.
Why the other options are wrong
- A. This summarizes the incident but doesn't deep dive into the 'why'.
- B. This lists chronological events, not the analytical findings of why the incident occurred.
- C. This section outlines future actions, not the analysis of past failures.
Lessons Learned - Root Cause Analysis
A component of a 'lessons learned' report that systematically investigates and identifies the fundamental reasons, such as control gaps or process failures, that contributed to an incident's occurrence or impact.
- Focuses on 'why' an incident happened.
- Identifies underlying control deficiencies or process breakdowns.
- Distinguishes between symptoms and fundamental causes.
Memory trick: Learned Lessons Reveal Core Problems and Fixes.