GCIH Incident Response and Cyber Investigation Practice Question
Which phase of the incident response process is most likely to involve the creation of a 'lessons learned' report to improve future security posture?
⚠ Common exam trap
Candidates often select containment or eradication phases when looking for long-term organizational improvement and post-incident reporting processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Post-Incident Activity
Post-Incident Activity, often referred to as the 'Lessons Learned' phase, is the final stage of the IR lifecycle. It is essential for organizational growth, allowing the team to reflect on the effectiveness of their response, identify gaps in detection or containment, and update playbooks. This continuous improvement cycle is what differentiates a maturing security program from one that repeats the same mistakes during recurring security incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detection and Analysis
Why it's wrong here
The Detection and Analysis phase focuses on identifying the incident and determining its scope. The primary output here is an incident report detailing what happened and what systems were affected, rather than a strategic review of how the organization can improve its overall IR capabilities for the future.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
This phase is dedicated to stopping the attacker and restoring business functions. While responders might note operational difficulties, the formal 'lessons learned' process occurs after the recovery is complete, as it requires a comprehensive retrospective that cannot be conducted while the team is under pressure to restore services.
- ✓
Post-Incident Activity
Why this is correct
The Post-Incident Activity phase is designed specifically for conducting a formal review of the incident response process. By documenting successes and failures, the organization can implement systemic changes to security controls, training, and response procedures, effectively closing the loop on the incident and enhancing future resilience.
- ✗
Preparation
Why it's wrong here
Preparation occurs before an incident happens. While lessons learned from previous incidents are used to improve preparation, the actual creation of a lessons learned report is a concluding task for a specific incident, not a task that happens during the pre-incident preparation and planning phase of the lifecycle.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.