CISSP · Free practice question 10 of 12
Lessons learned after incident closure
Glenmore Pharmaceuticals has just closed a significant phishing incident: affected accounts were reset and systems restored. What is the main purpose of the meeting the incident manager is now scheduling with everyone involved?
- A.To decide whether the original containment actions should be reversed
- B.To identify and discipline the employees who clicked the phishing link
- C.To start collecting volatile evidence from the affected endpoints
- D.To review the incident and the response, and agree on improvements
Show answer and explanation
Correct answer: D. To review the incident and the response, and agree on improvements
Why: The lessons learned review takes place after recovery and examines what happened, what worked, what did not and what should change, feeding improvements back into controls, detection and the response plan. Its purpose is improvement rather than blame, containment decisions belong to earlier phases, and volatile evidence must be collected at the start of an incident, long before closure.
More free CISSP questions
- Senior management ultimate security accountability
- Wassenaar Arrangement export of cryptography
- Brewer-Nash model prevents conflicts of interest
- Known-plaintext cryptanalytic attack
- Air-gapped network physical segmentation
- Role-based access control by job function
- Misuse case testing of abuse scenarios
- Breach and attack simulation platforms
- Proactive hypothesis-driven threat hunting
- Access control vestibule stops tailgating
- Cold site characteristics and recovery time