CISM · Question #33
Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:
The correct answer is B. tracked and reported on until their final resolution. After an unsuccessful DoS attack, identified weaknesses must be systematically tracked and reported until they are fully resolved to prevent future successful attacks.
Question
Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:
Options
- Anoted and re-examined later if similar weaknesses are found
- Btracked and reported on until their final resolution
- Cquickly resolved and eliminated regardless of cost
- Ddocumented in security awareness programs
How the community answered
(29 responses)- A7% (2)
- B86% (25)
- C3% (1)
- D3% (1)
Why each option
After an unsuccessful DoS attack, identified weaknesses must be systematically tracked and reported until they are fully resolved to prevent future successful attacks.
Merely noting weaknesses and re-examining them later is a reactive approach that does not guarantee resolution or prevent future incidents.
Post-incident analysis requires that all identified weaknesses, vulnerabilities, or gaps in defenses be formally tracked and reported upon, ensuring they are addressed and remediated, thereby strengthening the organization's security posture. This continuous tracking helps monitor progress and confirms resolution.
While quick resolution is ideal, eliminating weaknesses regardless of cost is not always a practical or economically feasible approach in business operations.
Documenting weaknesses in security awareness programs is not the primary action; awareness programs educate users, but do not directly remediate technical vulnerabilities.
Concept tested: Post-incident weakness management
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.