Question 1 of 30
Quality control measures reveal that a recent cybersecurity incident has significantly disrupted critical business operations. The incident response team is under immense pressure to restore services as quickly as possible to minimize financial losses. However, there are concerns that rushing the restoration process might compromise the thoroughness of the investigation and the accuracy of the post-incident report. Considering the need for both operational recovery and robust security accountability, which of the following approaches best optimizes the incident response lifecycle in this situation?
Prioritize the preservation of forensic evidence and conduct a detailed analysis of the incident's scope and impact before initiating full system restoration.
Immediately restore affected systems to normal operations, focusing solely on getting services back online, and address detailed investigation and documentation later.
Implement containment measures without meticulously documenting each step or its immediate impact, assuming the primary goal is to stop the spread of the threat.
Assign the entire post-incident analysis to a single senior analyst, expecting them to independently compile all findings and recommendations without formal team review.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free