ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 336 - CS0-003 discussion

Report
Export

A new SOC manager reviewed findings regarding the strengths and weaknesses of the last tabletop exercise in order to make improvements. Which of the following should the SOC manager utilize to improve the process?

A.

The most recent audit report

Answers
A.

The most recent audit report

B.

The incident response playbook

Answers
B.

The incident response playbook

C.

The incident response plan

Answers
C.

The incident response plan

D.

The lessons-learned register

Answers
D.

The lessons-learned register

Suggested answer: D

Explanation:

The lessons-learned register is an essential document that captures insights and feedback from past exercises or incidents, highlighting what went well and what did not. By utilizing this register, the SOC manager can identify specific areas for improvement and develop actionable steps to enhance future response efforts. According to CompTIA's CySA+ and Security+ guidance, lessons learned from tabletop exercises are crucial for iterative improvements in an incident response plan. Options A, B, and C are useful resources, but the lessons-learned register specifically focuses on reflection and improvement, which is the primary objective in this context.

asked 17/10/2024
Jose Manuel Belmonte Martinez
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first