ExamGecko
Question list
Search
Search

Related questions











Question 542 - CISA discussion

Report
Export

The operations team of an organization has reported an IS security attack Which of the following should be the FIRST step for the security incident response team?

A.
Report results to management
Answers
A.
Report results to management
B.
Document lessons learned
Answers
B.
Document lessons learned
C.
Perform a damage assessment
Answers
C.
Perform a damage assessment
D.
Prioritize resources for corrective action
Answers
D.
Prioritize resources for corrective action
Suggested answer: C

Explanation:

The first step for the security incident response team after an IS security attack is reported is to perform a damage assessment. This involves identifying the scope, impact and root cause of the incident, as well as collecting and preserving evidence for further analysis and investigation.Reporting results to management, documenting lessons learned and prioritizing resources for corrective action are important steps, but they should be done after the damage assessment is completed.Reference:CISA Review Manual (Digital Version), Chapter 6, Section 6.31

asked 18/09/2024
GLAUCIA C N SILVA
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first