GSEC Incident Handling and Response Practice Question
After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?
⚠ Common exam trap
The trap here is assuming the phase where the review occurs is the phase being improved, rather than the phase the finding addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
The finding that log sources were not integrated into the SIEM points to a gap in preparation. Preparation involves setting up logging, monitoring, and detection tools. By addressing this, the team enhances future detection capabilities. While the review occurs in Post-Incident Activity, the corrective action targets Preparation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preparation
Why this is correct
The lessons-learned meeting is part of the post-incident activity phase, but the specific finding about log integration directly addresses preparation. Improving log sources and SIEM integration enhances future readiness and detection capabilities. Preparation encompasses building and maintaining the tools and processes needed to respond effectively, so this finding aims to strengthen that phase.
- ✗
Detection and Analysis
Why it's wrong here
Detection and Analysis is the phase where the incident is identified and investigated. While the delayed detection occurred during this phase, the root cause was inadequate preparation. The finding is not about improving analysis techniques but about ensuring the necessary data is available beforehand. Thus, the corrective action targets preparation.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
This phase deals with limiting damage, removing the threat, and restoring systems. The issue described is about detection delays due to missing log integration, which is unrelated to containment or recovery actions. Improving these later phases would not address the root cause of the delayed detection.
- ✗
Post-Incident Activity
Why it's wrong here
Post-Incident Activity is the phase where the lessons-learned meeting takes place, but the finding itself is about improving preparation. The meeting is a mechanism to identify improvements, and here the improvement is to preparation. Selecting this phase would be circular, as it is the phase conducting the review, not the phase being improved.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.