nerdexam
Isaca

CISA · Question #45

Which of the following should be the FIRST step in the incident response process for a suspected breach?

The correct answer is D. Research the validity of the alerted breach.. The immediate first step in incident response for a suspected breach is to research and validate the alert to confirm it is a genuine incident.

Submitted by luis.pe· Apr 18, 2026Information Systems Operations and Business Resilience

Question

Which of the following should be the FIRST step in the incident response process for a suspected breach?

Options

  • AEngage a third party to independently evaluate the alerted breach.
  • BNotify business management of the security breach.
  • CInform potentially affected customers of the security breach.
  • DResearch the validity of the alerted breach.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • D
    92% (36)

Why each option

The immediate first step in incident response for a suspected breach is to research and validate the alert to confirm it is a genuine incident.

AEngage a third party to independently evaluate the alerted breach.

Engaging a third party is typically done after initial identification and assessment, especially for complex or confirmed incidents, not as the very first step when an alert is first received.

BNotify business management of the security breach.

Notifying business management is part of the communication plan, which follows the identification and initial assessment of a confirmed incident, not the validation of the initial alert.

CInform potentially affected customers of the security breach.

Informing potentially affected customers is a late-stage step in the incident response process, typically after containment, eradication, recovery, and legal notification requirements have been determined.

DResearch the validity of the alerted breach.Correct

The incident response process begins with the 'Identification' phase, where the primary objective is to determine if an actual security incident has occurred and assess its nature and scope. Researching the validity of the alerted breach prevents the allocation of resources to false positives and ensures subsequent, resource-intensive steps are taken only for confirmed incidents.

Concept tested: Incident response identification phase

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev2/final

Topics

#Incident Response#Breach Identification#Security Operations#Incident Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice