ExamGecko
Question list
Search
Search

Question 679 - CISM discussion

Report
Export

An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done

FIRST?

A.
Install additional application controls.
Answers
A.
Install additional application controls.
B.
Notify senior management.
Answers
B.
Notify senior management.
C.
Invoke the incident response plan.
Answers
C.
Invoke the incident response plan.
D.
Prevent access to the application.
Answers
D.
Prevent access to the application.
Suggested answer: C

Explanation:

According to the NIST SP 800-61 Computer Security Incident Handling Guide1, the first step in responding to a cybersecurity incident is to invoke the incident response plan (IRP), which is a written document that defines the roles, responsibilities, and procedures for dealing with a confirmed or suspected security breach1.The IRP helps the organization to prepare for, detect, analyze, contain, eradicate, recover from, and learn from incidents1. Invoking the IRP ensures that the right personnel and resources are mobilized to effectively deal with the threat and minimize the impact.

Reference=1: NIST SP 800-61: 1.Introduction1

asked 01/10/2024
josny Cameus
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first