CompTIA CySA+ CS0-003 Practice Question
Which of the following post-incident activities serves as the most comprehensive tool for an organization to evaluate its response to a security incident and to identify areas for improvement?
Updating documentation with incident details
Performing root cause analysis
Conducting a forensic analysis
Facilitating a 'lessons learned' meeting