ACME Corporation's SOC spent three days containing and eradicating a ransomware outbreak that affected several file servers. Backups have been validated, systems restored, and normal operations resumed. The incident-response manager schedules a 90-minute meeting with representatives from security, IT operations, legal, and business units one week after recovery. According to industry-standard incident-response life-cycle guidance, which activity should be the primary objective of this meeting, held during the lessons-learned phase?
Destroy volatile-memory captures and forensic images that are no longer needed to reduce storage costs.
Deploy temporary network-segmentation rules to isolate previously impacted servers while long-term patches are evaluated.
Draft and send statutory breach-notification letters to customers and regulators.
Facilitate a structured post-incident debrief that documents successes, shortcomings, and actionable improvements to update response playbooks and controls.
During the lessons-learned phase, the team's main goal is to perform a structured post-incident review. This debrief captures what worked, what failed, and why, then translates those insights into updates for playbooks, controls, and training. NIST SP 800-61 and SANS guidance both describe this continuous-improvement loop as the core purpose of post-incident activity. Purging evidence, drafting breach notifications, or re-deploying containment controls are legitimate tasks-but they belong to evidence-retention, notification/communications, and containment phases respectively, not to the lessons-learned meeting.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the lessons-learned phase in incident response?
Open an interactive chat with Bash
Why is it important to update playbooks and controls after an incident?
Open an interactive chat with Bash
What is NIST SP 800-61, and how does it relate to incident response?