ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A security team is conducting a post-incident review after a successful phishing attack led to a data breach. Their goal is to identify lessons learned, improve existing security measures, and update incident response plans to prevent similar incidents. This activity falls under which phase of incident response?
- AContainment
- BPost-Incident Activity
- CRecovery
- DEradication
Show answer & explanationAnswer & explanation
Correct answer: B. Post-Incident Activity
Post-incident activity, also known as lessons learned or post-mortem, is the final phase of incident response focused on reviewing the incident, documenting findings, and improving future response capabilities and overall security posture.
Why the other options are wrong
- A. Containment focuses on limiting the scope and impact of the incident.
- C. Recovery involves restoring systems and services to normal operation.
- D. Eradication aims to remove the cause of the incident, such as malware or vulnerabilities.
Post-Incident Activity
The final phase of incident response, involving review, documentation, and improvement of security measures and incident response plans after an incident has been resolved.
- Focuses on lessons learned.
- Aims to prevent recurrence.
- Includes updating policies and procedures.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Review: P.D.C.E.R.R.