Which THREE activities are typically performed during the post-incident activity phase of the incident response lifecycle?
Root cause analysis (RCA) is performed during the post-incident phase to identify the fundamental vulnerability or vector that allowed the compromise to occur. By pinpointing the exact failure point, security teams can implement permanent corrective controls rather than just treating the symptoms of the attack. This prevents future occurrences of the same exploit.
Why this answer
Root cause analysis (B) is performed during the post-incident activity phase to identify the underlying vulnerability or misconfiguration that allowed the incident to occur. This analysis informs remediation steps and helps prevent recurrence, making it a core activity of this phase.
Exam trap
CompTIA often tests the distinction between recovery-phase actions (e.g., system restoration) and post-incident analysis activities, leading candidates to mistakenly include restoration as a post-incident task.