During a ransomware containment event, your EDR analyst needed to isolate a compromised server but could not find an approved containment approver, delaying response. The post-incident review identified the missing approval path. What should the team do next?
Select an answer to reveal the explanation.
Short Explanation
Think of a containment playbook like a fire drill: if nobody knows who grabs the extinguisher, the fire gets bigger. You need a named approver and a fallback right in the playbook, not a vague note or a future meeting. That’s the fix that turns a lesson learned into action.
Full Explanation
The incident response process requires that lessons learned become concrete changes to procedures, playbooks, and approval matrices. When containment was delayed because no approver path existed, the actionable improvement is to name accountable approvers and a fallback in the containment playbook. That removes ambiguity during a live incident, preserves speed, and keeps containment decisions within the agreed authority model. Documenting the gap and waiting for a future policy review captures the finding but does not correct the broken workflow before the next incident. Requiring executive written approval for every containment action is too rigid and can create the same delay, especially when leadership is unavailable during an emergency. Adding a generic best-judgment note leaves the approval authority undefined and shifts risk to analysts without documented authority. Exam caveat: CS0-004 expects you to convert post-incident findings into specific process updates, not merely record observations. Operational check: revise the playbook to list primary, secondary, and emergency containment approvers, then tabletop-test the path with EDR and service owners.