nerdexam
Isaca

CISM · Question #46

Which of the following is the BEST way to improve an organization's ability to detect and respond to incidents?

The correct answer is B. Conduct periodic awareness training. To best improve an organization's ability to detect and respond to incidents, periodic awareness training should be conducted to empower employees as the first line of defense.

Submitted by khalil_dz· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the BEST way to improve an organization's ability to detect and respond to incidents?

Options

  • AConduct a business impact analysis (BIA).
  • BConduct periodic awareness training.
  • CPerform a security gap analysis.
  • DPerform network penetration testing.

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    75% (38)
  • C
    16% (8)
  • D
    4% (2)

Why each option

To best improve an organization's ability to detect and respond to incidents, periodic awareness training should be conducted to empower employees as the first line of defense.

AConduct a business impact analysis (BIA).

A business impact analysis (BIA) focuses on understanding the impact of disruptions and establishing recovery objectives, not on directly improving detection and response capabilities.

BConduct periodic awareness training.Correct

Periodic security awareness training educates employees to recognize and report suspicious activities, such as phishing attempts or unusual system behavior, significantly enhancing the organization's ability to detect incidents early. Timely detection by users enables a quicker and more effective response, often preventing minor issues from escalating into major security breaches.

CPerform a security gap analysis.

Performing a security gap analysis identifies weaknesses and informs potential improvements, but it is a diagnostic step rather than an direct action that improves detection and response capabilities itself.

DPerform network penetration testing.

Performing network penetration testing assesses existing vulnerabilities and tests defense mechanisms, which can improve response by identifying weaknesses, but it does not broadly enhance the entire organization's detection capability in the same way user awareness does for common attack vectors.

Concept tested: Security awareness for incident detection

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offer-risk-assessment-human-firewall-cybersecurity-guidance

Topics

#Security Awareness Training#Incident Detection#Incident Response#Human Factor

Community Discussion

No community discussion yet for this question.

Full CISM Practice