exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 150 discussion

Actual exam question from CompTIA's CS0-003
Question #: 150
Topic #: 1
[All CS0-003 Questions]

Which of the following actions would an analyst most likely perform after an incident has been investigated?

  • A. Risk assessment
  • B. Root cause analysis
  • C. Incident response plan
  • D. Tabletop exercise
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kmordalv
Highly Voted 1 year, 1 month ago
Selected Answer: B
After an incident has been investigated, one of the most important actions is to perform a root cause analysis. Root cause analysis helps in identifying the underlying reasons or factors that led to the incident in the first place. By understanding the root causes, organizations can implement corrective actions to prevent similar incidents from occurring in the future. This analysis is crucial for improving the overall security posture and resilience of the organization. The options A, C and D are typically done before an incident occurs
upvoted 6 times
...
[Removed]
Highly Voted 11 months, 2 weeks ago
Selected Answer: B
B A) risk assessment: done prior to an incident. This is a separate process outside of incident response B) Correct. After the incident, this is part of the lessons learned. Why did this happen? C) IRP this doesn't make sense in the context of the question D) tabletops are done to simulate an incident, preemptive. Not afterwards
upvoted 6 times
Sebatian20
10 months, 2 weeks ago
Investigate isn't fixing the issue. IRP is the only answer as you need to fix the problem before before you can do a lesson learn. This isn't a well worded question though; typical of Comptia.
upvoted 1 times
...
...
Chalice
Most Recent 7 months ago
It took me a bit to agree with root cause as the answer but after a while I got it. The root cause is the why it happened not what happened. The investigation covers the what and after that is concluded, then you focus on the why.
upvoted 3 times
...
Tdarling77
7 months ago
Answer D: Tabletop exercise. Here's my rationale: Conducting a risk assessment, root cause analysis, and developing an incident response plan are activities typically carried out before or during an incident investigation, rather than afterward. A risk assessment involves identifying, analyzing, and evaluating potential risks to the organization. Root cause analysis entails identifying the fundamental reasons behind an incident. An incident response plan outlines roles, responsibilities, procedures, and resources for responding to incidents. My emphasis is on the timing of these actions, which occur before or during, not after, an incident investigation.
upvoted 1 times
...
VVV4WIN
11 months, 1 week ago
After an incident has been remediated? Is that what they mean? If it has only been investigated, then has it only been discovered? Then IRP must occur..... But knowing CompTiA it is probably B
upvoted 3 times
...
Frog_Man
1 year ago
If an incident has been investigated, A and B should be complete and D does not apply. I say C. After the investigation has been completed, then we do a lessons learned and update the IRP as applicable.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago