CompTIA CySA+ (CS0-003) — Question 265
Which of the following is the most likely reason for an organization to assign different internal departmental groups during the post-incident analysis and improvement process?
Answer options
- A. To expose flaws in the incident management process related to specific work areas
- B. To ensure all staff members get exposure to the review process and can provide feedback
- C. To verify that the organization playbook was properly followed throughout the incident
- D. To allow cross-training for staff who are not involved in the incident response process
Correct answer: A
Explanation
The correct answer, A, highlights the importance of identifying specific weaknesses in the incident management process that may vary by department. Options B, C, and D, while valuable for other reasons, do not primarily focus on uncovering flaws in the incident management process itself.