nerdexam
EC-Council

312-38 · Question #33

Which of the following procedures is designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data…

The correct answer is A. Cyber Incident Response Plan. A Cyber Incident Response Plan (CIRP) is specifically designed to guide security personnel through detecting, containing, and recovering from malicious computer incidents - exactly what the question describes, including unauthorized access, denial-of-service, and tampering with…

Incident Response and Business Continuity

Question

Which of the following procedures is designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data, denial-of-service, or unauthorized changes to system hardware, software, or data?

Options

  • ACyber Incident Response Plan
  • BCrisis Communication Plan
  • CDisaster Recovery Plan
  • DOccupant Emergency Plan

How the community answered

(29 responses)
  • A
    93% (27)
  • B
    3% (1)
  • D
    3% (1)

Explanation

A Cyber Incident Response Plan (CIRP) is specifically designed to guide security personnel through detecting, containing, and recovering from malicious computer incidents - exactly what the question describes, including unauthorized access, denial-of-service, and tampering with systems or data.

  • B (Crisis Communication Plan) handles how an organization communicates with stakeholders (media, customers, employees) during a crisis - it's about messaging, not technical response.
  • C (Disaster Recovery Plan) focuses on restoring IT systems and operations after a broad disruption (natural disasters, major outages), not specifically malicious cyber events.
  • D (Occupant Emergency Plan) deals with physical safety of people in a building (fires, evacuations) - it has nothing to do with digital/cyber incidents.

Memory tip: The word "malicious computer incidents" is your anchor - only a Cyber Incident Response Plan targets malicious, cyber-specific threats. If the question mentions hacking, DoS, or data tampering, think CIRP.

Topics

#Incident Response#Incident Identification#Incident Recovery#Cyber Incidents

Community Discussion

No community discussion yet for this question.

Full 312-38 Practice