Courseiva

GSEC Incident Handling and Response Practice Question

After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?

⚠ Common exam trap

The trap here is assuming the phase where the review occurs is the phase being improved, rather than the phase the finding addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preparation

The finding that log sources were not integrated into the SIEM points to a gap in preparation. Preparation involves setting up logging, monitoring, and detection tools. By addressing this, the team enhances future detection capabilities. While the review occurs in Post-Incident Activity, the corrective action targets Preparation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Preparation

    Why this is correct

    The lessons-learned meeting is part of the post-incident activity phase, but the specific finding about log integration directly addresses preparation. Improving log sources and SIEM integration enhances future readiness and detection capabilities. Preparation encompasses building and maintaining the tools and processes needed to respond effectively, so this finding aims to strengthen that phase.

  • ✗

    Detection and Analysis

    Why it's wrong here

    Detection and Analysis is the phase where the incident is identified and investigated. While the delayed detection occurred during this phase, the root cause was inadequate preparation. The finding is not about improving analysis techniques but about ensuring the necessary data is available beforehand. Thus, the corrective action targets preparation.

  • ✗

    Containment, Eradication, and Recovery

    Why it's wrong here

    This phase deals with limiting damage, removing the threat, and restoring systems. The issue described is about detection delays due to missing log integration, which is unrelated to containment or recovery actions. Improving these later phases would not address the root cause of the delayed detection.

  • ✗

    Post-Incident Activity

    Why it's wrong here

    Post-Incident Activity is the phase where the lessons-learned meeting takes place, but the finding itself is about improving preparation. The meeting is a mechanism to identify improvements, and here the improvement is to preparation. Selecting this phase would be circular, as it is the phase conducting the review, not the phase being improved.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.