200-201 · Question #208
Refer to the exhibit. Which stakeholders must be involved when a company workstation is compromised?
The correct answer is D. Employee 2, Employee 3, Employee 4, Employee 5. A workstation compromise requires a multidisciplinary incident response, involving IT security for technical resolution, legal for compliance, HR for personnel matters, and the affected user for information.
Question
Refer to the exhibit. Which stakeholders must be involved when a company workstation is compromised?
Exhibit
Options
- AEmployee 1 Employee 2, Employee 3, Employee 4, Employee 5, Employee 7
- BEmployee 1, Employee 2, Employee 4, Employee 5
- CEmployee 4, Employee 6, Employee 7
- DEmployee 2, Employee 3, Employee 4, Employee 5
How the community answered
(31 responses)- A6% (2)
- B23% (7)
- C10% (3)
- D61% (19)
Why each option
A workstation compromise requires a multidisciplinary incident response, involving IT security for technical resolution, legal for compliance, HR for personnel matters, and the affected user for information.
This option includes roles (Employee 1, Employee 7) that are less directly involved in the immediate technical and organizational response to a compromise, potentially including general users or high-level executives who are informed rather than active responders.
This option omits Legal Counsel (Employee 3), a crucial stakeholder for addressing legal obligations and potential compliance issues arising from a data breach or system compromise.
This option omits key roles such as the IT/Security Team (Employee 2) responsible for technical remediation and the affected user (Employee 5) who can provide critical context.
Employee 2 (IT/Security Team), Employee 3 (Legal Counsel), Employee 4 (HR), and Employee 5 (Affected User) are all critical stakeholders in incident response, covering technical investigation, legal ramifications, personnel management, and user cooperation respectively.
Concept tested: Incident response stakeholders
Source: https://learn.microsoft.com/en-us/security/compass/incident-response-plan
Topics
Community Discussion
No community discussion yet for this question.
