The post-incident review process helps an organization identify gaps in its response and security posture. Assigning different departmental groups ensures that flaws in specific work areas (such as IT, HR, or legal teams) are identified and addressed. * Option B is incorrect because not all staff need exposure; the review focuses on relevant stakeholders. * Option C is a part of the process, but the main goal is improvement, not just playbook verification. * Option D (cross-training) is a benefit but not the main objective. Thus, A is the best answer because it focuses on identifying flaws in specific areas of incident management .