ExamGecko
Question list
Search
Search

Question 344 - CISM discussion

Report
Export

An incident management team leader sends out a notification that the organization has successfully recovered from a cyberattack. Which of the following should be done NEXT?

A.
Prepare an executive summary for senior management
Answers
A.
Prepare an executive summary for senior management
B.
Gather feedback on business impact
Answers
B.
Gather feedback on business impact
C.
Conduct a meeting to capture lessons learned.
Answers
C.
Conduct a meeting to capture lessons learned.
D.
Secure and preserve digital evidence for analysis.
Answers
D.
Secure and preserve digital evidence for analysis.
Suggested answer: C

Explanation:

Conducting a meeting to capture lessons learned is the next step after an incident management team leader sends out a notification that the organization has successfully recovered from a cyberattack because it helps to identify the strengths and weaknesses of the current incident response plan, capture the feedback and recommendations from the incident responders and stakeholders, and implement the necessary improvements and corrective actions for future incidents. Preparing an executive summary for senior management is not the next step, but rather a subsequent step that involves reporting the incident details, impact, and resolution to the senior management. Gathering feedback on business impact is not the next step, but rather a concurrent step that involves assessing the extent and severity of the damage or disruption caused by the incident. Securing and preserving digital evidence for analysis is not the next step, but rather a previous step that involves collecting and documenting the relevant data or artifacts related to the incident.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned

asked 01/10/2024
Yunus Emre Akay
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first