We use cookies to ensure you get the best user experience. For more information see our cookie policy.
To access material, start machines and answer questions login.
The attacker has been contained, eradicated, and the environment is clean. But the work is not finished. The final phase of the incident response framework is Post-Incident Activity, the phase where the organization steps back, reflects on what happened, documents the findings, and uses everything learned to become harder to attack next time.
Although this room can be completed as a standalone, it is highly recommended to complete the following rooms before starting this one:
Familiarity with queries is required for the practical tasks. It is also recommended to complete the Microsoft 365 for the module before starting this room.
This module follows a single security incident at Nexus Financial from start to finish across four rooms:
| Room | What You Do |
|---|---|
| 1 - Preparation | Review Nexus Financial's security posture before the attack |
| 2 - Detection and Analysis | Detect the incident and analyze it in |
| 3 - Response and Recovery | Make containment decisions, confirm the attacker is gone, and identify root causes |
| 4 - Post-Incident Activity | Reconstruct the timeline of the attack and revisit what went wrong |
Note: This is Room 4 of 4 in the Incident Response module. This room brings everything together and closes the cycle.
I am ready to start!
The Post-Incident Activity room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in