An IR team is responding to a business email compromise where an attacker used a compromised executive's email account. During post-incident activity, which lesson-learned item is MOST valuable?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because post-incident activity should identify root cause failures in preventive controls — why did phishing bypass email filters, why was MFA not enforced — and implement concrete technical improvements to prevent recurrence. B is wrong because IP blacklisting provides minimal future value as attackers change infrastructure frequently.
Full explanation below image
Full Explanation
A is correct because post-incident activity should identify root cause failures in preventive controls — why did phishing bypass email filters, why was MFA not enforced — and implement concrete technical improvements to prevent recurrence. B is wrong because IP blacklisting provides minimal future value as attackers change infrastructure frequently. C is wrong because financial impact documentation is important but not the most valuable security lesson learned. D is wrong because awareness training alone without technical controls is insufficient to prevent recurrence.