ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 228 - CS0-003 discussion

Report
Export

Which of the following actions would an analyst most likely perform after an incident has been investigated?

A.
Risk assessment
Answers
A.
Risk assessment
B.
Root cause analysis
Answers
B.
Root cause analysis
C.
Incident response plan
Answers
C.
Incident response plan
D.
Tabletop exercise
Answers
D.
Tabletop exercise
Suggested answer: D

Explanation:

A tabletop exercise is the most likely action that an analyst would perform after an incident has been investigated. A tabletop exercise is a simulation of a potential incident scenario that involves the key stakeholders and decision-makers of the organization. The purpose of a tabletop exercise is to evaluate the effectiveness of the incident response plan, identify the gaps and weaknesses in the plan, and improve the communication and coordination among the incident response team and other parties. A tabletop exercise can help the analyst to learn from the incident investigation, test the assumptions and recommendations made during the investigation, and enhance the preparedness and resilience of the organization for future incidents12. Risk assessment, root cause analysis, and incident response plan are all actions that an analyst would perform before or during an incident investigation, not after. Risk assessment is the process of identifying, analyzing, and evaluating the risks that may affect the organization. Root cause analysis is the method of finding the underlying or fundamental causes of an incident. Incident response plan is the document that defines the roles, responsibilities, procedures, and resources for responding to an incident345.

Reference: Tabletop Exercises: Six Scenarios to Help Prepare Your Cybersecurity Team, Tabletop Exercises for Incident Response - SANS Institute, Risk Assessment - NIST, Root Cause Analysis - OWASP, Incident Response Plan | Ready.gov

asked 02/10/2024
Joan Campo
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first