CISSP - Security Operations - Section 7.6

Conduct incident management including detection, response, mitigation, reporting, recovery, remediation, and lessons learned.

Conduct incident management across all phases - detection, containment, eradication, recovery, and lessons learned - following a structured incident response plan. Apply the lessons learned output to update controls, response procedures, and detection rules so that the same incident type cannot recur undetected.

incident responsedetectioncontainmenteradicationlessons learned

Practice question for this objective

Free sampleSecurity Operationshard

Six weeks after a successful business email compromise that caused a fraudulent supplier payment, the incident has been closed and funds partially recovered. The CISO has asked the incident manager to run the lessons-learned activity. Which approach should the incident manager take as the PRIMARY focus of the session?

  • AIdentify the individual finance approver whose failure to verify the bank detail change allowed the payment, so HR can address performance.
  • BDocument a detailed technical reconstruction of the phishing email and attacker infrastructure for inclusion in the threat intelligence repository.
  • CExamine the timeline against the incident response plan to identify control, process, and detection gaps, and agree owned actions to close them. Correct
  • DDraft updated awareness training content about supplier impersonation and schedule a mandatory refresh for the finance department.
Run lessons learned as a structured review against the incident response plan that produces owned, tracked improvements. Lessons learned is the closing phase of the incident response lifecycle and is the mechanism by which an organisation reduces the probability and impact of similar incidents. A structured review walks the actual timeline against the IR plan, surfaces gaps across prevention, detection, response, communication, and recovery, and assigns owners and dates to the resulting actions. Focusing on a single individual, a single artefact, or a single corrective action all narrow the review and leave systemic weaknesses in place.

Why A is wrong: Singling out an individual creates a blame culture, discourages future reporting, and ignores the systemic controls that should have prevented a single point of failure. CISSP guidance is to treat lessons learned as a process improvement activity, not a disciplinary one.

Why B is wrong: A technical reconstruction is a useful artefact but is a narrow slice of lessons learned. Stopping there misses process, governance, and human-factor lessons that drive most BEC losses and that the CISO needs to act on.

Why C is correct: The post-incident review exists to convert the incident into durable improvement. Comparing what happened to the plan exposes gaps in prevention, detection, response, and communication, and assigning owned actions with due dates is what turns the review into measurable risk reduction.

Why D is wrong: Updated training is a plausible output of the review but is one possible action, not the focus of the session itself. Jumping to a single corrective action without analysing the full timeline tends to leave detection and process gaps unaddressed.

See more CISSP practice questions with worked answers.

More in this domain

Back to all Security Operations objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.