Why Should Root Cause Analysis Be Part of Incident Response?
Which of the following describes the reason root cause analysis should be conducted as part of incident response?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can separate RCA's forward-looking prevention goal from the containment, eradication, and scoping activities that belong to earlier incident response phases, and the trap is picking a task that RCA merely feeds into rather than its actual objective.
Root cause analysis during incident response exists to find the underlying weakness that allowed an incident to occur so the same failure can be prevented from recurring. This page confirms that preventing future incidents of the same nature (D) is the purpose of RCA, not evidence collection, scope determination, or malware cleanup.
Many candidates choose B, 'To discover which systems have been affected,' because scoping feels analytical and blurs into root-cause work; however, identifying affected systems is part of detection, analysis, and containment, whereas RCA exists specifically to stop the same incident from happening again.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Root cause analysis is performed after an incident has been contained and eradicated, and its whole purpose is to ask "why did this succeed?" rather than "what happened?" The deliverable of RCA is a remediation plan against the underlying weakness — a missing patch, an over-permissive rule, a failed control, a process gap — so that the same class of incident cannot recur. Option D captures exactly that forward-looking prevention objective and matches the standard incident response doctrine in NIST SP 800-61 and SY0-701 Objective 4.8. As dbrowndiver put it here, RCA is about "addressing the underlying issues rather than merely treating the symptoms," which is also how the community framed it. Every commenter in this thread landed on the same reading, and the reasoning is sound rather than merely popular.Why the Other Options Are Wrong
Option A, gathering IoCs, is part of detection and analysis — IoCs describe what the attacker did, not why the defense failed. Option B, discovering which systems are affected, is scoping, which must happen early during detection and containment so responders know where to act; it is an input to RCA, not its reason for existing. Option C, eradicating any trace of malware, describes the eradication phase of incident response, and removing malware without understanding its entry path guarantees the same intrusion returns. Only D describes the outcome that justifies spending time on RCA at all: breaking the cycle so the incident does not repeat.Community Comment Notes
Abcd123321 states that root cause analysis "Identifies the incident's source and how to prevent it in the future," which is the cleanest one-line justification in the thread. 0ca8ee9 adds the practical bluntness of it — "Without RCA, we can't prevent repeats" — reinforcing that prevention is the driver. f71cbb0 simply notes "that's the purpose of root cause," and MaxiPrince's answer echoes the same wording as option D. No commenter argued for A, B, or C, so there is no dissenting reasoning to weigh against the doctrine.Official Reference
Exam Strategy
Watch the verb in these 'reason/purpose' questions: if the option describes a phase activity (scope, contain, eradicate, collect evidence), it is a distractor for why RCA is done after the fact. Map each option to an incident response phase — preparation, detection and analysis, containment, eradication, recovery, lessons learned — and pick the one tied to lessons learned and prevention.
Frequently Asked Questions
Why is gathering IoCs not the reason RCA is performed?
IoCs are collected during detection and analysis to characterize the attack; RCA instead looks past the indicators to find why the control failed so the incident cannot recur.
How does RCA differ from eradicating malware on the network?
Eradication removes the malware currently present, while RCA identifies the entry path and weakness that let it in, preventing the same intrusion from returning later.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →