nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #717

Which of the following is a best practice for security incident response?

The correct answer is D. Having a clearly defined incident response plan in place. Having a clearly defined incident response plan (IRP) in place before an incident occurs is a fundamental best practice. An IRP ensures that when a security incident happens, the team knows exactly what steps to take, who is responsible, and how to contain and recover…

Security Operations

Question

Which of the following is a best practice for security incident response?

Options

  • AIgnoring security incidents to avoid drawing attention to them
  • BWaiting until an incident occurs to develop an incident response plan
  • CNone of the above
  • DHaving a clearly defined incident response plan in place

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    3% (1)
  • D
    90% (36)

Explanation

Having a clearly defined incident response plan (IRP) in place before an incident occurs is a fundamental best practice. An IRP ensures that when a security incident happens, the team knows exactly what steps to take, who is responsible, and how to contain and recover - reducing confusion, response time, and damage. Option A (ignoring incidents) is dangerous and can lead to regulatory violations and greater harm. Option B (waiting until an incident to plan) leaves the organization unprepared and reactive. Option C ('none of the above') is incorrect because D is clearly a valid best practice.

Topics

#Incident Response#Security Planning#Best Practices#Cybersecurity Operations

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice