Which of the following is the MOST important outcome of a post-incident review?
A.
The impact of the incident is reported to senior management.
B.
The system affected by the incident is restored to its prior state.
C.
The person responsible for the incident is identified.
D.
The root cause of the incident is determined.
The Answer Is:
D
This question includes an explanation.
Explanation:
Determining the root cause of the incident is essential for preventing or minimizing the recurrence of similar incidents, as well as for identifying and implementing corrective actions to improve the security posture of the organization.