ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 277 - CS0-003 discussion

Report
Export

A security team conducts a lessons-learned meeting after struggling to determine who should conduct the next steps following a security event. Which of the following should the team create to address this issue?

A.
Service-level agreement
Answers
A.
Service-level agreement
B.
Change management plan
Answers
B.
Change management plan
C.
Incident response plan
Answers
C.
Incident response plan
D.
Memorandum of understanding
Answers
D.
Memorandum of understanding
Suggested answer: C

Explanation:

An incident response plan (IRP) is a document that defines the roles and responsibilities, procedures, and guidelines for responding to a security incident. It helps the security team to act quickly and effectively, minimizing the impact and cost of the incident. An IRP should specify who should conduct the next steps following a security event, such as containment, eradication, recovery, and analysis12.

Reference: CompTIA CySA+ CS0-003 Certification Study Guide, page 362; 6 Incident Response Steps to Take After a Security Event, section 2.

asked 02/10/2024
Damien Fenderson
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first