Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy
A security analyst is reviewing an organization's incident response plan and notices a gap in how sensitive data breaches are handled. The current plan focuses primarily on system restoration but lacks specific steps for notifying affected parties and regulatory bodies. Which critical aspect of incident response is missing?
- AContainment, Eradication, and Recovery
- BPreparation
- CPost-Incident Activities
- DIncident Identification
Show answer & explanationAnswer & explanation
Correct answer: C. Post-Incident Activities
Notifying affected parties and regulatory bodies, along with lessons learned and evidence retention, are all crucial components of post-incident activities. The scenario specifically highlights the absence of these steps.
Why the other options are wrong
- A. Containment, Eradication, and Recovery are phases that occur during the active incident, not after it has been resolved.
- B. Preparation involves establishing policies, training, and tools before an incident occurs.
- D. Incident Identification is about recognizing an event as an incident, which is not the focus here.
Post-Incident Activities
Actions taken after an incident has been contained, eradicated, and recovered from, including documentation, lessons learned, and mandatory notifications.
- Crucial for continuous improvement and compliance.
- Involves detailed reporting and analysis.
- Often includes legal and regulatory obligations.
Memory trick: PREPARE, DETECT, CONTAIN, ERADICATE, RECOVER, POST-MORTEM.