CAS-005 · Question #431
A security manager has written an incident response playbook for insider attacks and is ready to begin testing it. Which of the following should the manager conduct to test the playbook?
The correct answer is D. Threat emulation. Threat emulation (also known as adversary or red-team simulation) involves deliberately mimicking insider tactics, techniques, and procedures to validate the playbook’s controls and procedures in a controlled exercise. This approach directly tests whether the detection, containme
Question
A security manager has written an incident response playbook for insider attacks and is ready to begin testing it. Which of the following should the manager conduct to test the playbook?
Options
- AAutomated vulnerability scanning
- BCentralized logging, data analytics, and visualization
- CThreat hunting
- DThreat emulation
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- C12% (3)
- D80% (20)
Explanation
Threat emulation (also known as adversary or red-team simulation) involves deliberately mimicking insider tactics, techniques, and procedures to validate the playbook’s controls and procedures in a controlled exercise. This approach directly tests whether the detection, containment, and response steps work as designed against realistic insider behaviors.
Community Discussion
No community discussion yet for this question.