ExamGecko
Question list
Search
Search

Question 675 - CISM discussion

Report
Export

Predetermined containment methods to be used in a cybersecurity incident response should be based PRIMARILY on the:

A.
number of impacted users.
Answers
A.
number of impacted users.
B.
capability of incident handlers.
Answers
B.
capability of incident handlers.
C.
type of confirmed incident.
Answers
C.
type of confirmed incident.
D.
predicted incident duration.
Answers
D.
predicted incident duration.
Suggested answer: C

Explanation:

According to the NIST SP 800-61 Computer Security Incident Handling Guide, the type of confirmed incident is one of the most important criteria for choosing a containment strategy, as different types of incidents may require different levels of urgency, scope, and impact1. For example, a denial-of-service attack may require a different containment strategy than a ransomware attack or a data breach.

Reference=1: NIST SP 800-61: 3.1.Choosing a Containment Strategy2

asked 01/10/2024
Srikar Gude
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first