An incident is declared resolved after eradication and recovery. The PICERL model requires one final phase. What activities occur in this phase?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the Lessons Learned phase (the final 'L' in PICERL) involves a post-incident review to capture findings, update playbooks, adjust controls, and improve future response. A is wrong because hunting for additional compromised hosts is part of Identification and Eradication, not the final Lessons Learned phase.
Full explanation below image
Full Explanation
B is correct because the Lessons Learned phase (the final 'L' in PICERL) involves a post-incident review to capture findings, update playbooks, adjust controls, and improve future response. A is wrong because hunting for additional compromised hosts is part of Identification and Eradication, not the final Lessons Learned phase. C is wrong because blanket re-imaging is a containment/eradication action, not a lessons-learned activity. D is wrong because mass password resets are a remediation action taken during recovery, not the lessons-learned phase.