ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 494 - CAS-004 discussion

Report
Export

A Chief Information Security Officer (CISO) received a call from the Chief Executive Officer (CEO) about a data breach from the SOC lead around 9:00 a.m. At 10:00 a.m. The CEO informs the CISO that a breach of the firm is being reported on national news. Upon investigation, it is determined that a network administrator has reached out to a vendor prior to the breach for information on a security patch that failed to be installed. Which of the following should the CISO do to prevent this from happening again?

A.
Properly triage events based on brand imaging and ensure the CEO is on the call roster.
Answers
A.
Properly triage events based on brand imaging and ensure the CEO is on the call roster.
B.
Create an effective communication plan and socialize it with all employees.
Answers
B.
Create an effective communication plan and socialize it with all employees.
C.
Send out a press release denying the breach until more information can be obtained.
Answers
C.
Send out a press release denying the breach until more information can be obtained.
D.
Implement a more robust vulnerability identification process.
Answers
D.
Implement a more robust vulnerability identification process.
Suggested answer: B

Explanation:

To prevent similar issues from occurring again, the CISO should create an effective communication plan and ensure all employees are aware of it. A clear communication plan ensures that critical security information, such as breaches or vulnerabilities, is promptly communicated to the right stakeholders (e.g., the CEO) in a timely manner, preventing situations where the media reports on breaches before internal teams are fully informed. CASP+ emphasizes the importance of having structured communication protocols during security incidents to ensure accurate and timely responses.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Incident Communication Plans)

CompTIA CASP+ Study Guide: Developing and Implementing Effective Incident Communication Plans

asked 02/10/2024
Gbena Wale
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first