exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 419 discussion

Actual exam question from CompTIA's CAS-004
Question #: 419
Topic #: 1
[All CAS-004 Questions]

A multinational organization was hacked, and the incident response team’s timely action prevented a major disaster. Following the event, the team created an after action report. Which of the following is the primary goal of an after action review?

  • A. To gather evidence for subsequent legal action
  • B. To determine the identity of the attacker
  • C. To identify ways to improve the response process
  • D. To create a plan of action and milestones
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cf13076
6 months, 3 weeks ago
Selected Answer: C
C. To identify ways to improve the response process After action reviews are conducted to assess the effectiveness of the response process, identify any gaps or weaknesses, and determine how the organization can improve its incident response in the future. It is not primarily focused on gathering legal evidence or identifying attackers but rather on learning from the incident to enhance security practices.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago