Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingHard
An organization is reviewing its incident response capabilities. They have robust tools for threat detection and prevention, but lack a structured process for conducting post-incident reviews, documenting lessons learned, and updating policies and procedures. Which critical component of a comprehensive incident response program is currently underdeveloped?
- ASecurity Information and Event Management (SIEM)
- BPost-Incident Activity
- CReal-time Threat Intelligence Feed
- DForensic Analysis Toolkit
Show answer & explanationAnswer & explanation
Correct answer: B. Post-Incident Activity
Post-Incident Activity is the phase dedicated to learning from incidents, improving processes, and documenting outcomes. The description explicitly mentions the lack of structured processes for post-incident reviews, lessons learned, and policy updates, directly pointing to this phase.
Why the other options are wrong
- A. SIEM is for detection and analysis, which they already have.
- C. Threat intelligence feeds are part of preparation and detection, not post-incident improvement.
- D. A forensic toolkit is a specific set of tools, not a phase or process component.
Post-Incident Activity
The final phase of incident response, focusing on learning from the incident, documenting findings, improving processes, and updating policies to prevent recurrence.
- Includes creating incident reports and conducting 'lessons learned' meetings (hot washes).
- Aims for continuous improvement of the incident response plan.
- Ensures vulnerabilities exploited are addressed and policies are updated.
Memory trick: After the incident, review, learn, and grow.