Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingEasy

A security team is conducting a post-incident review after a significant data breach. They are analyzing the timeline of events, the effectiveness of their response actions, and identifying areas for improvement in their processes and technologies. Which of the following incident handling concepts is this activity primarily focused on?

  1. AEvidence Preservation
  2. BLessons Learned
  3. CIncident Prioritization
  4. DContainment Strategy
Show answer & explanation

Correct answer: B. Lessons Learned

The post-incident review process, which involves analyzing the incident, response effectiveness, and identifying improvements, is the core activity of 'Lessons Learned'. This phase aims to enhance future incident response capabilities.

Why the other options are wrong

  • A. Evidence preservation occurs during and after the incident for legal/forensic needs.
  • C. Prioritization occurs at the start of an incident to rank its importance.
  • D. Containment strategy is developed and executed during the active incident phase.

Lessons Learned

A critical component of the post-incident phase where an organization reviews the incident response process to identify strengths, weaknesses, and areas for improvement.

  • Involves analyzing the incident timeline and response actions.
  • Aims to improve incident response plans, tools, and training.
  • Contributes to organizational security maturity.

Memory trick: After the Fire, Learn and Improve.

More Incident Handling questions