SSCP Systems Security Certified PractitionerIncident Response and RecoveryMedium

A security team is performing a post-incident review following a successful phishing attack that led to credential compromise. Which of the following activities is a primary objective of the 'Lessons Learned' phase?

  1. AIdentifying and patching the vulnerability exploited by the attacker.
  2. BDocumenting the timeline of the incident and identifying areas for improvement.
  3. CEnsuring legal and regulatory compliance for breach notification.
  4. DRestoring affected user accounts and systems.
Show answer & explanation

Correct answer: B. Documenting the timeline of the incident and identifying areas for improvement.

The 'Lessons Learned' phase focuses on reviewing the incident, documenting its details, and identifying opportunities to improve incident response capabilities and overall security posture.

Why the other options are wrong

  • A. Patching vulnerabilities is part of the eradication phase, which aims to remove the root cause.
  • C. Ensuring compliance for breach notification is typically part of the recovery or post-incident communication, but not the primary objective of 'Lessons Learned' itself.
  • D. Restoring accounts and systems is part of the recovery phase.

Lessons Learned (Incident Response)

The final phase of incident response, focused on reviewing the incident, documenting findings, and identifying improvements to prevent future incidents and enhance response capabilities.

  • Occurs after recovery.
  • Involves a post-incident review meeting.
  • Aims to improve policies, procedures, and training.

Memory trick: Learn from mistakes, get better next time!

More Incident Response and Recovery questions