PrepAway - Latest Free Exam Questions & Answers

which step are you in?

In the course of responding to and handling an incident, you work on determining the root cause of the incident.
In which step are you in?

PrepAway - Latest Free Exam Questions & Answers

A.
Recovery

B.
Containment

C.
Triage

D.
Analysis and tracking

Explanation:
Root cause analysis, which is part of analysis and tracking steps, is an intensive process to determine why
something happened and how to prevent it in the future.
Incorrect Answers:
A: Recovery does not include finding the cause of the problem.
B: A proper containment strategy buys the incident response team time for a proper investigation and
determination of the incident’s root cause, but the containment step does not include finding the root cause.
C: Triage would be the first step, prior to finding the root cause of the problem, and includes estimating the
severity of the incident.

Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 1039


Leave a Reply