exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 213 discussion

Actual exam question from CompTIA's SY0-601
Question #: 213
Topic #: 1
[All SY0-601 Questions]

A security analyst needs to produce a document that details how a security incident occurred, the steps that were taken for recovery, and how future incidents can be avoided. During which of the following stages of the response process will this activity take place?

  • A. Recovery
  • B. Identification
  • C. Lessons learned
  • D. Preparation
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
garlandboy
Highly Voted 2 years, 7 months ago
Agree with C
upvoted 7 times
...
Gino_Slim
Highly Voted 2 years, 6 months ago
Selected Answer: C
This is Lessons Learned. This takes place after everything has a occurred and the team is trying to figure out how to do better. Also, for anyone that has reached this point and realized that they discussions have become less and less. That's because a month ago the questions stopped at #211. So from here on out it's just the newer participants.
upvoted 6 times
...
ApplebeesWaiter1122
Most Recent 1 year, 9 months ago
Selected Answer: C
During this stage, the incident response team conducts a post-mortem analysis of the incident to identify what went wrong, what worked well, and what could be improved. The goal is to gain insights and knowledge from the incident so that the organization can enhance its security posture and response capabilities for the future. The lessons learned document may include a detailed analysis of the incident timeline, the root cause of the incident, the actions taken during the response, and the effectiveness of those actions. It may also include recommendations for improving security controls, policies, and procedures to prevent similar incidents in the future. This document serves as a valuable resource for learning from the incident and enhancing the organization's incident response capabilities.
upvoted 2 times
...
rodwave
2 years, 5 months ago
Selected Answer: C
Answer: Lessons learned Lessons learned or remediation step is the final phase of the incident response. It examines and documents how well the team responded, discovers what caused the incident, and determines how the incident can be avoided in the future. ======================= Phases of the Incident Response Plan: 1. Preparation - Preparing for an attack and how to respond 2. Identification - Identifying the threat 3. Containment - Containing the threat 4. Eradication - Removing the threat 5. Recovery - Recovering affected systems 6. Lessons Learned - Evaluating the incident response, see where there can be improvements for a future incident.
upvoted 4 times
...
Sir_Learnalot
2 years, 5 months ago
Selected Answer: C
CompTIA really love lessons learned...get the feeling like every incident response process question is about lessons learned
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago