A food plant finishes restoring a recipe controller after malware. The team wants to apply the last NIST SP 800-61 phase. Which action fits it?
- A.Disable the infected account in the directory
- B.Capture memory from the HMI before restart
- C.Add a signature to the plant intrusion sensor
- D.Hold a lessons learned review with operators
Why D is correct
Post-incident activity is the review of what happened and how to improve, ideally with operations in the room. Disabling accounts and memory capture belong to containment and analysis and sensor rules are an improvement made afterward.
Know someone studying for OT Security Fundamentals? Send them this one.