新しい SOC マネージャーは、改善を行うために、前回のテーブルトップ演習の長所と短所に関する調査結果を確認しました。SOC マネージャーは、プロセスを改善するために次のどれを活用すべきでしょうか。
正解:D
The lessons-learned register is an essential document that captures insights and feedback from past exercises or incidents, highlighting what went well and what did not. By utilizing this register, the SOC manager can identify specific areas for improvement and develop actionable steps to enhance future response efforts.
According to CompTIA's CySA+ and Security+ guidance, lessons learned from tabletop exercises are crucial for iterative improvements in an incident response plan. Options A, B, and C are useful resources, but the lessons-learned register specifically focuses on reflection and improvement, which is the primary objective in this context.