exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 58 discussion

Actual exam question from CompTIA's SY0-701
Question #: 58
Topic #: 1
[All SY0-701 Questions]

During an investigation, an incident response team attempts to understand the source of an incident. Which of the following incident response activities describes this process?

  • A. Analysis
  • B. Lessons learned
  • C. Detection
  • D. Containment
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hasquaati
Highly Voted 7 months, 1 week ago
Selected Answer: A
Answer is A because you need to conduct an analysis to find out what the source of the incident was.
upvoted 7 times
...
darpanne
Most Recent 4 days, 12 hours ago
Selected Answer: A
In the Analysis phase, the team examines logs, network traffic, artifacts, and other relevant data to determine: The root cause of the incident How the incident occurred The systems and data affected Indicators of Compromise (IOCs) Possible paths for remediation and prevention
upvoted 1 times
...
89fdeb4
6 days, 6 hours ago
Selected Answer: A
It can't be "Lessons learned" because we're still investigating. "During an Investigation"
upvoted 2 times
...
racer99_
1 month ago
Selected Answer: B
This q tripped me up for a long time until i looked up the IRP stages. If you look it up you'll see that "Lessons learned" includes finding out what the source of the incident was. There is no such "analysis" stage in IRP. Correct answer here is B
upvoted 1 times
...
sireyml
1 month ago
Selected Answer: A
Emphasis on "During an investigation". During an incident response, analysis refers to the process of investigating and understanding the source of the incident, including determining how the incident occurred, identifying the root cause, and gathering the necessary evidence to support further actions. This is a key part of incident response where the team works to fully comprehend the nature of the incident and its origins. "Lessons learned" is an activity that takes place after the incident has been resolved.
upvoted 2 times
...
chalaka
1 month, 2 weeks ago
Selected Answer: A
A. Analysis In the incident response process, analysis involves examining evidence and data to determine the cause and source of an incident. This phase helps the incident response team understand how the incident occurred, who or what caused it, and the extent of its impact.
upvoted 1 times
...
3dk1
2 months ago
Going with A. The problem with B is that it is post incident, this question is "During an investigation". I agree that you will investigate the root cause in the Lessons Learned portion as well, but this is at the END, not during.
upvoted 2 times
nyyankee718
1 month, 4 weeks ago
It said "During an investigation" NOT during the incident so B
upvoted 1 times
...
...
c7b3ff0
2 months, 1 week ago
Selected Answer: B
Lessons Learned - Review severe incidents to determine the root cause, whether they were avoidable, and how to avoid them in the future. Analysis - determine if an incident has actually occurred and assign it a priority level.
upvoted 2 times
...
deejay2
2 months, 1 week ago
I think lessons learned is the right answer. Lesson's learned deals with post recovery(not during the investigation) and meets with everyone that was affected by the incident to get feedback and learn ways to improve to prevent this from happening next time. Analysis deals with the incident while the incident is happening, not after.
upvoted 1 times
...
nap61
2 months, 2 weeks ago
Selected Answer: B
From CompTIA Security Guide Analysis - After the detection process reports one or more indicators, in the analysis process, the first responder investigates the data to determine whether a genuine incident has been identified and what level of priority it should be assigned. Conversely, the report might be categorized as a false positive and dismissed. Lessons Learned - The lessons learned process reviews severe security incidents to determine their root cause, whether they were avoidable, and how to avoid them in the future. The lessons learned process should invoke root cause analysis or the effort to determine how the incident was able to occur. A lot of models have been developed to structure root cause analysis. One is the “Five Whys” model. This starts with a statement of the problem and then poses successive “Why” questions to drill down to root causes. So, to understand the source of incident, or root cause, in in LESSONS LEARNED.
upvoted 3 times
...
cyoncon
2 months, 2 weeks ago
B, post incident
upvoted 1 times
...
Sol_tyty
4 months ago
Selected Answer: A
GPT!!!
upvoted 1 times
...
Etc_Shadow28000
6 months, 1 week ago
Selected Answer: A
A. Analysis During an investigation, the incident response team engages in the process of understanding the source of an incident through analysis. This involves examining the data and evidence collected to determine how the incident occurred, its origin, and its impact. Therefore, the correct answer is: A. Analysis
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago