ExamGecko
Question list
Search
Search

Question 148 - CISM discussion

Report
Export

An incident management team is alerted to a suspected security event. Before classifying the suspected event as a security incident, it is MOST important for the security manager to:

A.
conduct an incident forensic analysis.
Answers
A.
conduct an incident forensic analysis.
B.
fallow the incident response plan
Answers
B.
fallow the incident response plan
C.
notify the business process owner.
Answers
C.
notify the business process owner.
D.
fallow the business continuity plan (BCP).
Answers
D.
fallow the business continuity plan (BCP).
Suggested answer: B

Explanation:

Before classifying the suspected event as a security incident, it is most important for the security manager to follow the incident response plan, which is a predefined set of procedures and guidelines that outline the roles, responsibilities, and actions of the incident management team and the organization in the event of a security event or incident. Following the incident response plan can help to ensure a consistent, coordinated, and effective response to the suspected event, as well as to minimize the impact and damage to the business processes, functions, and assets. Following the incident response plan can also help to determine the nature, scope, and severity of the suspected event, and to decide whether it meets the criteria and threshold for being classified as a security incident that requires further escalation, investigation, and resolution. Following the incident response plan can also help to document and report the incident details, activities, and outcomes, and to provide feedback and recommendations for improvement and optimization of the incident response process and plan.

Conducting an incident forensic analysis, notifying the business process owner, and following the business continuity plan (BCP) are all important steps in the incident response process, but they are not the most important ones before classifying the suspected event as a security incident. Conducting an incident forensic analysis is a technical and detailed process that involves collecting, preserving, analyzing, and presenting evidence related to the incident, and it is usually performed after the incident has been classified, contained, and eradicated. Notifying the business process owner is a communication and notification process that involves informing the relevant stakeholders of the incident status, impact, and actions, and it is usually performed after the incident has been classified and assessed.Following the business continuity plan (BCP) is a recovery and restoration process that involves resuming and restoring the normal business operations and functions after the incident has been resolved and lessons learned have been identified and implemented.Reference= CISM Review Manual 15th Edition, pages 237-2411; CISM Practice Quiz, question 1422

asked 01/10/2024
Amar Lojo
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first