During an incident, an analyst isolated a critical file server because a host alert matched a containment playbook, causing an outage. The containment was later judged incorrect. After restoring service, the team prepares a lessons-learned review. What should be the review’s primary focus?
Select an answer to reveal the explanation.
Short Explanation
Think of a post-incident review like fixing the road, not yelling at the driver. You want to know why the playbook, alert data, or telemetry let the wrong containment happen. If you don’t blame the system first, the real gaps stay hidden and the next incident repeats the same mistake.
Full Explanation
A blameless lessons-learned review exists to improve the response system after containment errors. In this scenario, the analyst followed a playbook that produced an incorrect action, so the review should examine whether alert context, asset criticality data, playbook logic, approval thresholds, or telemetry visibility were missing. That focus supports continuous improvement, reduces recurrence, and preserves a reporting culture where analysts surface near misses. A review centered on individual discipline changes the purpose from learning to accountability and can suppress honest reporting, even if a policy breach occurred. Mandatory training before containment may help skill gaps, but it does not explain why the playbook or telemetry failed and can delay addressing systemic flaws. Adding universal approval gates may reduce some accidental actions, yet it introduces operational friction and can worsen response time if applied without risk-based criteria. Exam caveat: CS0-004 post-incident questions often reward process improvement, root-cause analysis, and communication over punitive personnel action. Operational check: After restoring service, list each containment decision point and identify the telemetry, asset data, or playbook rule that should have prevented the incorrect isolation.