Which of the following describes the reason root cause analysis should be conducted as part of incident response?
Choose an answer
Tap an option to check your answer.
Correct answer: To prevent future incidents of the same nature.
Why this is the answer
Root cause analysis (RCA) is performed to identify the fundamental reason an incident occurred, not just the symptoms. By understanding the root cause, an organization can implement corrective actions to prevent similar incidents from happening again, thereby improving overall security posture. While gathering Indicators of Compromise (IoCs) and discovering affected systems are crucial steps in the incident response process, they are part of the initial investigation and containment phases, not the primary goal of RCA. Eradicating malware is also a containment and recovery step, focusing on the immediate threat rather than the underlying cause that allowed the malware to enter or execute.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed