nerdexam
Isaca

CISM · Question #33

Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:

The correct answer is B. tracked and reported on until their final resolution. After an unsuccessful DoS attack, identified weaknesses must be systematically tracked and reported until they are fully resolved to prevent future successful attacks.

Submitted by javi_es· Apr 18, 2026Information Security Incident Management

Question

Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:

Options

  • Anoted and re-examined later if similar weaknesses are found
  • Btracked and reported on until their final resolution
  • Cquickly resolved and eliminated regardless of cost
  • Ddocumented in security awareness programs

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    86% (25)
  • C
    3% (1)
  • D
    3% (1)

Why each option

After an unsuccessful DoS attack, identified weaknesses must be systematically tracked and reported until they are fully resolved to prevent future successful attacks.

Anoted and re-examined later if similar weaknesses are found

Merely noting weaknesses and re-examining them later is a reactive approach that does not guarantee resolution or prevent future incidents.

Btracked and reported on until their final resolutionCorrect

Post-incident analysis requires that all identified weaknesses, vulnerabilities, or gaps in defenses be formally tracked and reported upon, ensuring they are addressed and remediated, thereby strengthening the organization's security posture. This continuous tracking helps monitor progress and confirms resolution.

Cquickly resolved and eliminated regardless of cost

While quick resolution is ideal, eliminating weaknesses regardless of cost is not always a practical or economically feasible approach in business operations.

Ddocumented in security awareness programs

Documenting weaknesses in security awareness programs is not the primary action; awareness programs educate users, but do not directly remediate technical vulnerabilities.

Concept tested: Post-incident weakness management

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Management#Vulnerability Management#Remediation Tracking#Post-incident Activities

Community Discussion

No community discussion yet for this question.

Full CISM Practice