CAS-003 · Question #868
A security manager is creating an incident response plan for an organization. Executive management wants to designate a specific group of personnel to respond to incidents and an additional group to…
The correct answer is B. Threat hunters D. CIRT. The scenario has two distinct requirements: (1) a group to respond to active incidents, and (2) a group to perform proactive threat detection before incidents occur. A CIRT (Computer Incident Response Team) is formed specifically to respond to security incidents…
Question
A security manager is creating an incident response plan for an organization. Executive management wants to designate a specific group of personnel to respond to incidents and an additional group to perform more proactive threat detection before an active incident occurs. Which of the following groups must be formed to satisfy these requirements? (Choose two.)
Options
- ACRM
- BThreat hunters
- CGovernance board
- DCIRT
- ERisk committee
- FBusiness analysts
How the community answered
(31 responses)- A3% (1)
- B87% (27)
- C6% (2)
- F3% (1)
Explanation
The scenario has two distinct requirements: (1) a group to respond to active incidents, and (2) a group to perform proactive threat detection before incidents occur. A CIRT (Computer Incident Response Team) is formed specifically to respond to security incidents - investigating, containing, and remediating active threats. Threat hunters proactively search the environment for hidden adversaries, indicators of compromise, and attack precursors that have not yet triggered alerts, satisfying the pre-incident detection requirement. CRM (A) is customer relationship management. A governance board (C) and risk committee (E) are oversight bodies, not operational security teams. Business analysts (F) focus on process and data analysis, not threat response or detection.
Topics
Community Discussion
No community discussion yet for this question.