nerdexam
(ISC)2

CGRC · Question #246

The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's information system(s). Respo

The correct answer is A. Incident Response Plan. An Incident Response Plan is a documented set of procedures designed to detect, respond to, and mitigate the impact of malicious cyberattacks on an organization's information systems. Its purpose is to guide personnel through the stages of a security incident to minimize damage a

Implementation of Security and Privacy Controls

Question

The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's information system(s). Response:

Options

  • AIncident Response Plan
  • BContingency Plan
  • COperations Plan
  • DDisaster Recovery Plan

How the community answered

(59 responses)
  • A
    86% (51)
  • B
    2% (1)
  • C
    7% (4)
  • D
    5% (3)

Why each option

An Incident Response Plan is a documented set of procedures designed to detect, respond to, and mitigate the impact of malicious cyberattacks on an organization's information systems. Its purpose is to guide personnel through the stages of a security incident to minimize damage and recovery time.

AIncident Response PlanCorrect

An Incident Response Plan (IRP) is specifically designed to address the detection, analysis, containment, eradication, recovery, and post-incident activities related to security incidents, including malicious cyberattacks. It provides a structured approach for an organization to manage and respond to security breaches and cyber threats effectively, thereby limiting their consequences.

BContingency Plan

A Contingency Plan generally addresses disruptions to IT systems or operations due to various events (e.g., power outage, equipment failure), which can include security incidents but is broader than just malicious cyberattacks.

COperations Plan

An Operations Plan outlines routine day-to-day operational procedures, not specific responses to cyberattacks.

DDisaster Recovery Plan

A Disaster Recovery Plan (DRP) focuses on recovering IT infrastructure and operations after a major disaster (natural or man-made) that causes significant downtime, often involving restoring systems from backups in an alternate location.

Concept tested: Purpose of an Incident Response Plan

Source: https://csrc.nist.gov/glossary/term/incident_response_plan

Topics

#Incident Response Plan#Cyber Attack Response#Security Controls

Community Discussion

No community discussion yet for this question.

Full CGRC Practice