Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy
A cybersecurity analyst is reviewing an organization's incident response plan. They notice that the plan clearly defines roles and responsibilities for each team member, outlines communication protocols, and specifies technical procedures for containment and eradication. However, the plan lacks a formal process for identifying and documenting lessons learned after an incident. Which phase of the incident response lifecycle is most directly impacted by this omission?
- APost-Incident Activity
- BContainment, Eradication, and Recovery
- CDetection and Analysis
- DPreparation
Show answer & explanationAnswer & explanation
Correct answer: A. Post-Incident Activity
The absence of a formal process for identifying and documenting lessons learned directly impacts the Post-Incident Activity phase, which focuses on improving future response efforts.
Why the other options are wrong
- B. Containment, Eradication, and Recovery deals with active incident handling.
- C. Detection and Analysis focuses on identifying and understanding an ongoing incident.
- D. Preparation involves proactive measures before an incident, not post-incident review.
Post-Incident Activity
The final phase of the incident response lifecycle, focusing on reviewing the incident, documenting lessons learned, and implementing improvements.
- Occurs after an incident is resolved and systems are recovered.
- Aims to prevent similar incidents and improve future response.
- Includes activities like reporting, evidence retention, and plan updates.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-mortem.