CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is preparing a 'lessons learned' report after a significant data breach. The report aims to identify systemic weaknesses and recommend improvements to prevent future incidents. Which section of the report should detail the organizational processes, human factors, and technological gaps that contributed to the incident?

  1. ARecommendations
  2. BExecutive Summary
  3. CRoot Cause Analysis
  4. DIncident Timeline
Show answer & explanation

Correct answer: C. Root Cause Analysis

The Root Cause Analysis section of a lessons learned report is specifically designed to delve into the underlying systemic issues, including organizational processes, human factors, and technological gaps, that directly contributed to the incident, rather than just describing what happened or summarizing the findings.

Why the other options are wrong

  • A. The Recommendations section focuses on future actions, based on the analysis, but does not detail the contributing factors themselves.
  • B. The Executive Summary provides a high-level overview, not detailed analysis.
  • D. The Incident Timeline outlines the sequence of events, not the contributing factors.

Lessons Learned Report: Root Cause Analysis

The Root Cause Analysis section in a lessons learned report identifies the fundamental, underlying reasons for an incident, moving beyond immediate symptoms to uncover systemic issues across processes, people, and technology.

  • Goes beyond 'what happened' to 'why it happened'.
  • Includes analysis of human error, process failures, and technical vulnerabilities.
  • Forms the basis for effective recommendations.

Memory trick: Lessons Learned: Executive Summary, Timeline, Root Cause, Recommendations.

More Reporting and Communication questions