Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingHard

An organization is reviewing its incident response capabilities. They have robust tools for threat detection and prevention, but lack a structured process for conducting post-incident reviews, documenting lessons learned, and updating policies and procedures. Which critical component of a comprehensive incident response program is currently underdeveloped?

  1. ASecurity Information and Event Management (SIEM)
  2. BPost-Incident Activity
  3. CReal-time Threat Intelligence Feed
  4. DForensic Analysis Toolkit
Show answer & explanation

Correct answer: B. Post-Incident Activity

Post-Incident Activity is the phase dedicated to learning from incidents, improving processes, and documenting outcomes. The description explicitly mentions the lack of structured processes for post-incident reviews, lessons learned, and policy updates, directly pointing to this phase.

Why the other options are wrong

  • A. SIEM is for detection and analysis, which they already have.
  • C. Threat intelligence feeds are part of preparation and detection, not post-incident improvement.
  • D. A forensic toolkit is a specific set of tools, not a phase or process component.

Post-Incident Activity

The final phase of incident response, focusing on learning from the incident, documenting findings, improving processes, and updating policies to prevent recurrence.

  • Includes creating incident reports and conducting 'lessons learned' meetings (hot washes).
  • Aims for continuous improvement of the incident response plan.
  • Ensures vulnerabilities exploited are addressed and policies are updated.

Memory trick: After the incident, review, learn, and grow.

More Incident Handling questions