ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 481 - CAS-004 discussion

Report
Export

After investigating a recent security incident, a SOC analyst is charged with creating a reference guide for the entire team to use. Which of the following should the analyst create to address future incidents?

A.
Root cause analysis
Answers
A.
Root cause analysis
B.
Communication plan
Answers
B.
Communication plan
C.
Runbook
Answers
C.
Runbook
D.
Lessons learned
Answers
D.
Lessons learned
Suggested answer: C

Explanation:

A runbook is a detailed guide that provides step-by-step instructions on how to respond to specific types of incidents. It is used by the SOC team to ensure a consistent, organized, and efficient response to incidents. In this case, after the incident investigation, creating a runbook would help standardize the response process for future security incidents, enabling the team to act quickly and effectively. CASP+ emphasizes the importance of having detailed runbooks for incident response as part of an organization's overall incident response strategy.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Incident Response and Runbooks)

CompTIA CASP+ Study Guide: Incident Response Procedures and Runbooks

asked 02/10/2024
Gary Cox
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first