ExamGecko
Question list
Search
Search

Question 390 - CISM discussion

Report
Export

While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the plan?

A.
While responding to the incident
Answers
A.
While responding to the incident
B.
During a tabletop exercise
Answers
B.
During a tabletop exercise
C.
During post-incident review
Answers
C.
During post-incident review
D.
After a risk reassessment
Answers
D.
After a risk reassessment
Suggested answer: C

Explanation:

During post-incident review is the best time to update the incident response plan after observing several deficiencies in the current plan while responding to a high-profile security incident. A post-incident review is a process of analyzing and evaluating the incident response activities, identifying the lessons learned, and documenting the recommendations and action items for improvement. Updating the incident response plan during post-incident review helps to ensure that the plan reflects the current best practices, addresses the gaps and weaknesses, and incorporates the feedback and suggestions from the incident response team and other stakeholders. Therefore, during post-incident review is the correct answer.

https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf

https://www.techtarget.com/searchsecurity/feature/5-critical-steps-to-creating-an-effective-incident-response-plan

https://www.integrify.com/blog/posts/incident-response-plan-need-an-update/

asked 01/10/2024
Eissa Abdulrahman Eissa
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first