ExamGecko
Question list
Search
Search

Question 481 - CISM discussion

Report
Export

Which of the following should be the PRIMARY focus of a lessons learned exercise following a successful response to a cybersecurity incident?

A.
Establishing the root cause of the incident
Answers
A.
Establishing the root cause of the incident
B.
Identifying attack vectors utilized in the incident
Answers
B.
Identifying attack vectors utilized in the incident
C.
When business operations were restored after the incident
Answers
C.
When business operations were restored after the incident
D.
How incident management processes were executed
Answers
D.
How incident management processes were executed
Suggested answer: D

Explanation:

The primary focus of a lessons learned exercise following a successful response to a cybersecurity incident is to evaluate how the incident management processes were executed, and to identify the strengths, weaknesses, best practices, and improvement opportunities for future incidents. A lessons learned exercise is not meant to determine the root cause, the attack vectors, or the recovery time of the incident, but rather to assess the performance and effectiveness of the incident response team and the incident response plan.

asked 01/10/2024
Miles Greenyer
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first