nerdexam
Isaca

CISM · Question #29

Which type of plan is PRIMARILY intended to reduce the potential impact of security events that may occur?

The correct answer is A. Incident response plan. An incident response plan is primarily designed to reduce the potential impact of security events by providing structured procedures for detecting, analyzing, containing, eradicating, and recovering from incidents.

Submitted by weili_xi· Apr 18, 2026Information Security Incident Management

Question

Which type of plan is PRIMARILY intended to reduce the potential impact of security events that may occur?

Options

  • AIncident response plan
  • BBusiness continuity plan (BCP)
  • CSecurity awareness plan
  • DDisaster recovery plan (DRP)

How the community answered

(48 responses)
  • A
    88% (42)
  • B
    8% (4)
  • C
    2% (1)
  • D
    2% (1)

Why each option

An incident response plan is primarily designed to reduce the potential impact of security events by providing structured procedures for detecting, analyzing, containing, eradicating, and recovering from incidents.

AIncident response planCorrect

An incident response plan outlines the specific steps an organization will take when a security incident occurs, focusing on prompt detection, containment, eradication, and recovery. Its primary goal is to minimize the damage and disruption caused by security events, thereby reducing their potential impact on business operations and data.

BBusiness continuity plan (BCP)

A Business Continuity Plan (BCP) focuses on maintaining critical business functions during and after a disruption, which might include security events, but its scope is broader than just security events and it often relies on DRP for technical recovery.

CSecurity awareness plan

A security awareness plan aims to prevent incidents by educating employees, rather than reducing the impact of an event once it has occurred.

DDisaster recovery plan (DRP)

A Disaster Recovery Plan (DRP) focuses on restoring IT infrastructure and systems after a major disaster, which can include security events, but the incident response plan is more specific to security events and their immediate handling.

Concept tested: Purpose of an incident response plan

Source: https://learn.microsoft.com/en-us/security/compass/incident-response-overview

Topics

#Incident Response#Security Planning#Impact Reduction#Incident Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice