ExamGecko
Question list
Search
Search

Related questions











Question 696 - CISA discussion

Report
Export

Which of the following is MOST important for an IS auditor to confirm when reviewing an organization's incident response management program?

A.
All incidents have a severity level assigned.
Answers
A.
All incidents have a severity level assigned.
B.
All identified incidents are escalated to the CEO and the CISO.
Answers
B.
All identified incidents are escalated to the CEO and the CISO.
C.
Incident response is within defined service level agreements (SLAs).
Answers
C.
Incident response is within defined service level agreements (SLAs).
D.
The alerting tools and incident response team can detect incidents.
Answers
D.
The alerting tools and incident response team can detect incidents.
Suggested answer: D

Explanation:

The most important aspect of an incident response management program is the ability to detect incidents in a timely and accurate manner. Without effective detection, the organization cannot respond to incidents, mitigate their impact, or prevent their recurrence. The alerting tools and incident response team are responsible for monitoring the IT environment, identifying anomalies or threats, and notifying the appropriate stakeholders.

Reference

ISACA CISA Review Manual, 27th Edition, page 255

What is an incident response plan? And why do you need one?

ISACA CISA Certified Information Systems Auditor Exam ... - PUPUWEB

asked 18/09/2024
Norman Camacho
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first