nerdexam
CompTIA

CAS-003 · Question #426

Following a recent data breach, a company has hired a new Chief Information Security Officer (CISO). The CISO is very concerned about the response time to the previous breach and wishes to know how…

The correct answer is C. Conduct a tabletop exercise. A tabletop exercise is a discussion-based simulation where the security team walks through a hypothetical attack scenario step-by-step without touching live systems. It is specifically designed to evaluate incident response readiness while causing zero operational disruption…

Enterprise Security Operations

Question

Following a recent data breach, a company has hired a new Chief Information Security Officer (CISO). The CISO is very concerned about the response time to the previous breach and wishes to know how the security team expects to react to a future attack. Which of the following is the BEST method to achieve this goal while minimizing disruption?

Options

  • APerform a black box assessment
  • BHire an external red team audit
  • CConduct a tabletop exercise.
  • DRecreate the previous breach.
  • EConduct an external vulnerability assessment.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    89% (31)
  • D
    3% (1)

Explanation

A tabletop exercise is a discussion-based simulation where the security team walks through a hypothetical attack scenario step-by-step without touching live systems. It is specifically designed to evaluate incident response readiness while causing zero operational disruption. This directly satisfies the CISO's two goals: understanding how the team would react, and minimizing disruption. A black box assessment (A) or external red team (B) tests defenses but disrupts operations and doesn't specifically test the response team's process. Recreating the previous breach (D) is dangerous and disruptive. An external vulnerability assessment (E) identifies weaknesses but doesn't test response procedures.

Topics

#incident response#tabletop exercise#security assessment#business continuity

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice