ExamGecko
Question list
Search
Search

Question 112 - CISM discussion

Report
Export

An incident management team is alerted ta a suspected security event. Before classifying the suspected event as a security incident, it is MOST important for the security manager to:

A.
notify the business process owner.
Answers
A.
notify the business process owner.
B.
follow the business continuity plan (BCP).
Answers
B.
follow the business continuity plan (BCP).
C.
conduct an incident forensic analysis.
Answers
C.
conduct an incident forensic analysis.
D.
follow the incident response plan.
Answers
D.
follow the incident response plan.
Suggested answer: D

Explanation:

= Following the incident response plan is the most important step for the security manager before classifying the suspected event as a security incident, as it provides the guidance and procedures for the incident management team to follow in order to identify, contain, analyze, and resolve security incidents.The incident response plan should define the roles and responsibilities of the incident management team, the criteria and process for incident classification and prioritization, the communication and escalation protocols, the tools and resources for incident handling, and the post-incident review and improvement activities123.Reference=

1: CISM Review Manual 15th Edition, page 199-2004

2: CISM Practice Quiz, question 1011

3: Computer Security Incident Handling Guide5, page 2-3

asked 01/10/2024
Mathijs Sijm
25 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first