ExamGecko
Question list
Search
Search

Question 10 - CISM discussion

Report
Export

The PRIMARY objective of a post-incident review of an information security incident is to:

A.
update the risk profile
Answers
A.
update the risk profile
B.
minimize impact
Answers
B.
minimize impact
C.
prevent recurrence.
Answers
C.
prevent recurrence.
D.
determine the impact
Answers
D.
determine the impact
Suggested answer: C

Explanation:

post-incident review of an information security incident is a process that aims to identify the root causes, contributing factors, and lessons learned from the incident, and to implement corrective and preventive actions to avoid or mitigate similar incidents in the future. The primary objective of a post-incident review is to prevent recurrence, as it helps to improve the security posture, awareness, and resilience of the organization. Preventing recurrence also helps to reduce the impact and cost of future incidents, as well as to enhance the reputation and trust of the organization.Updating the risk profile, minimizing impact, and determining the impact are not the primary objectives of a post-incident review, although they may be part of its outcomes or outputs.Reference= CISM Review Manual, 16th Edition, page 1011

asked 01/10/2024
Bhavya AGGARWAL
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first