Study. uk . com
  1. Home
  2. All questions
  3. Question 529

CompTIA Security+ study material · question 529 of 611

What question does root cause analysis ask that an incident timeline does not?

  1. Which systems were affected
  2. Why was the incident possible at all
  3. What did the attacker do, and in what order
  4. How long did the attacker remain undetected
Show the answer

Answer: B. Why was the incident possible at all

That question is what turns one incident into a systemic fix rather than a single remediation.

Challenge yourself on this topic → Study as cards