During a major incident, multiple security teams are working simultaneously. The incident commander wants to ensure that decisions are documented and actions are coordinated. Which document serves as the central record of all incident actions, decisions, and timestamps?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because an incident logbook (or electronic equivalent in a SIEM/IR case management tool) captures every action, observation, and decision with timestamps during active response — essential for coordination between teams, accountability, and reconstruction of the response timeline. A is wrong because the IR policy is a procedural document created before incidents; it guides response but does not record real-time actions.
Full explanation below image
Full Explanation
B is correct because an incident logbook (or electronic equivalent in a SIEM/IR case management tool) captures every action, observation, and decision with timestamps during active response — essential for coordination between teams, accountability, and reconstruction of the response timeline. A is wrong because the IR policy is a procedural document created before incidents; it guides response but does not record real-time actions. C is wrong because the lessons-learned report is a post-incident document created after closure, not a real-time action log. D is wrong because the SIEM alert queue shows detection alerts but does not capture analyst actions, decisions, or narrative context.