exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 152 discussion

Actual exam question from CompTIA's SY0-601
Question #: 152
Topic #: 1
[All SY0-601 Questions]

A security incident has been resolved. Which of the following BEST describes the importance of the final phase of the incident response plan?

  • A. It examines and documents how well the team responded, discovers what caused the incident, and determines how the incident can be avoided in the future.
  • B. It returns the affected systems back into production once systems have been fully patched, data restored, and vulnerabilities addressed.
  • C. It identifies the incident and the scope of the breach, how it affects the production environment, and the ingress point.
  • D. It contains the affected systems and disconnects them from the network, preventing further spread of the attack or breach.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rodwave
Highly Voted 2 years, 7 months ago
Selected Answer: A
Answer: It examines and documents how well the team responded, discovers what caused the incident, and determines how the incident can be avoided in the future. The final phase of the incident response is also called the lessons learned or remediation step. ======================= Phases of the Incident Response Plan: 1. Preparation - Preparing for an attack and how to respond 2. Identification - Identifying the threat 3. Containment - Containing the threat 4. Eradication - Removing the threat 5. Recovery - Recovering affected systems 6. Lessons Learned - Evaluating the incident response, see where there can be improvements for a future incident.
upvoted 13 times
...
LordJaraxxus
Most Recent 1 year, 3 months ago
Selected Answer: A
Yep, lessons learned. The answer it's A
upvoted 1 times
...
7308365
1 year, 4 months ago
A. It examines and documents how well the team responded, discovers what caused the incident, and determines how the incident can be avoided in the future.
upvoted 1 times
...
Protract8593
1 year, 10 months ago
Selected Answer: A
The final phase of the incident response plan is crucial for evaluating the effectiveness of the response, identifying any weaknesses in the incident handling process, understanding the root cause of the incident, and implementing measures to prevent similar incidents in the future. It involves conducting a post-incident analysis and generating a comprehensive report with recommendations for improvement.
upvoted 1 times
...
Jossie_C
2 years, 7 months ago
Remediation AKA lessons learned
upvoted 1 times
...
RonWonkers
2 years, 9 months ago
Selected Answer: A
I agree, the other steps were Identification, containment and recovery, It is A, lessons learned
upvoted 3 times
...
Danalyst
2 years, 9 months ago
'Lessons Learned'
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...