CISM · Question #114
An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done FIRST?
The correct answer is C. Invoke the incident response plan.. When threat actors exploit a critical vulnerability, the first action should be to invoke the incident response plan to ensure a structured and coordinated response.
Question
An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done FIRST?
Options
- ANotify senior management.
- BPrevent access to the application.
- CInvoke the incident response plan.
- DInstall additional application controls.
How the community answered
(43 responses)- A12% (5)
- B7% (3)
- C79% (34)
- D2% (1)
Why each option
When threat actors exploit a critical vulnerability, the first action should be to invoke the incident response plan to ensure a structured and coordinated response.
Notifying senior management is an important step within the incident response plan, often occurring after initial assessment and containment.
Preventing access to the application (containment) is a critical step in incident response, but it is part of executing the incident response plan, not the very first action before the plan is formally engaged.
Invoking the incident response plan immediately establishes a structured framework for addressing the confirmed compromise, coordinating necessary actions, and defining roles and responsibilities. This ensures an organized and efficient approach to contain, eradicate, recover from, and post-analyze the incident, preventing chaotic or uncoordinated reactions.
Installing additional application controls is part of eradication and recovery, which comes after containment and is guided by the incident response plan.
Concept tested: Incident response plan initiation
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.