SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A company has recently experienced a data breach due to a phishing attack. As part of the post-incident activities, the security team is reviewing the incident to understand what happened, why it happened, and how to prevent similar incidents in the future. Which of the following best describes this phase?
- ALessons Learned
- BEradication
- CDetection
- DRecovery
Show answer & explanationAnswer & explanation
Correct answer: A. Lessons Learned
The 'Lessons Learned' phase (part of Post-Incident Activity) involves reviewing the entire incident response process, identifying strengths and weaknesses, and making recommendations for improvements to policies, procedures, and controls to prevent future incidents. This directly matches the scenario's description.
Why the other options are wrong
- B. Eradication focuses on removing the threat from the environment.
- C. Detection is the initial phase of identifying an incident.
- D. Recovery focuses on restoring systems and services to normal operation.
Lessons Learned (Incident Response)
A critical post-incident activity where the incident response team reviews the incident, the response actions, and their effectiveness to identify areas for improvement in policies, procedures, and security controls.
- Occurs after recovery.
- Aims to improve future incident handling.
- Identifies root causes and vulnerabilities.
- Includes updates to policies and training.
Memory trick: After the storm, we learn to fix the roof.