ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 290 - CS0-003 discussion

Report
Export

An incident response analyst is taking over an investigation from another analyst. The investigation has been going on for the past few days. Which of the following steps is most important during the transition between the two analysts?

A.
Identify and discuss the lessons learned with the prior analyst.
Answers
A.
Identify and discuss the lessons learned with the prior analyst.
B.
Accept all findings and continue to investigate the next item target.
Answers
B.
Accept all findings and continue to investigate the next item target.
C.
Review the steps that the previous analyst followed.
Answers
C.
Review the steps that the previous analyst followed.
D.
Validate the root cause from the prior analyst.
Answers
D.
Validate the root cause from the prior analyst.
Suggested answer: C

Explanation:

Reviewing the steps that the previous analyst followed is the most important step during the transition, as it ensures continuity and consistency of the investigation. It also helps the new analyst to understand the current status, scope, and findings of the investigation, and to avoid repeating the same actions or missing any important details. The other options are either less important, premature, or potentially biased.

Reference: CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 4: Incident Response and Management, page 191. Incident response best practices and tips, Tip 1: Always pack a jump bag.

asked 02/10/2024
Stephen DeWhite
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first