ExamGecko
Question list
Search
Search

Question 257 - CISM discussion

Report
Export

Which of the following is the BEST way for an organization to ensure that incident response teams are properly prepared?

A.
Providing training from third-party forensics firms
Answers
A.
Providing training from third-party forensics firms
B.
Obtaining industry certifications for the response team
Answers
B.
Obtaining industry certifications for the response team
C.
Conducting tabletop exercises appropriate for the organization
Answers
C.
Conducting tabletop exercises appropriate for the organization
D.
Documenting multiple scenarios for the organization and response steps
Answers
D.
Documenting multiple scenarios for the organization and response steps
Suggested answer: C

Explanation:

The BEST way for an organization to ensure that incident response teams are properly prepared is by conducting tabletop exercises appropriate for the organization.

Tabletop exercises are an effective way to test and validate an organization's incident response plan (IRP) and the readiness of the incident response team. These exercises simulate different scenarios in a controlled environment and allow the team to practice their response procedures, identify gaps, and make improvements to the plan. By conducting regular tabletop exercises, the incident response team can stay current with changes in the threat landscape and ensure that they are prepared to respond to incidents effectively.

According to the Certified Information Security Manager (CISM) Study Manual, 'Tabletop exercises are a valuable tool for testing and validating the effectiveness of the IRP and the readiness of the incident response team. These exercises simulate different scenarios in a controlled environment and allow the team to practice their response procedures, identify gaps, and make improvements to the plan.'

While providing training from third-party forensics firms, obtaining industry certifications, and documenting multiple scenarios for the organization and response steps can all be useful in preparing incident response teams, they are not as effective as conducting tabletop exercises appropriate for the organization.

Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 324.

asked 01/10/2024
Diego Beltran
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first