ExamGecko
Question list
Search
Search

Question 370 - CISM discussion

Report
Export

Which of the following should be triggered FIRST when unknown malware has infected an organization's critical system?

A.
Incident response plan
Answers
A.
Incident response plan
B.
Disaster recovery plan (DRP)
Answers
B.
Disaster recovery plan (DRP)
C.
Business continuity plan (BCP)
Answers
C.
Business continuity plan (BCP)
D.
Vulnerability management plan
Answers
D.
Vulnerability management plan
Suggested answer: A

Explanation:

The document that should be triggered first when unknown malware has infected an organization's critical system is the incident response plan because it defines the roles and responsibilities, procedures and protocols, tools and techniques for responding to and managing a security incident effectively and efficiently. Disaster recovery plan (DRP) is not a good document for this purpose because it focuses on restoring the organization's critical systems and operations after a major disruption or disaster, which may not be necessary or appropriate at this stage. Business continuity plan (BCP) is not a good document for this purpose because it focuses on restoring the organization's critical business functions and operations after a major disruption or disaster, which may not be necessary or appropriate at this stage. Vulnerability management plan is not a good document for this purpose because it focuses on identifying and evaluating the security weaknesses or exposures of the organization's systems and assets, which may not be relevant or helpful at this stage.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned

asked 01/10/2024
Janina Loveria
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first