CISM · Question #63
Which of the following is MOST important for effective cybersecurity incident management?
The correct answer is A. Early detection and response. Early detection and response are paramount for effective cybersecurity incident management, as they significantly reduce the impact and spread of an attack.
Question
Which of the following is MOST important for effective cybersecurity incident management?
Options
- AEarly detection and response
- BRegular tabletop exercises
- CRoot cause analysis
- DInvestigation and forensics
How the community answered
(64 responses)- A92% (59)
- B2% (1)
- C2% (1)
- D5% (3)
Why each option
Early detection and response are paramount for effective cybersecurity incident management, as they significantly reduce the impact and spread of an attack.
Early detection and response are most important for effective cybersecurity incident management because they directly minimize the impact, scope, and duration of an incident. Swift identification and containment of a threat prevent further damage, reduce recovery costs, and limit data exfiltration or system compromise, making all subsequent incident management steps more manageable and effective.
Regular tabletop exercises are valuable for *improving* incident management readiness, but they are not the *management itself* or its most critical component.
Root cause analysis is crucial for preventing future incidents but occurs *after* the immediate response and recovery, making it less important for the *effectiveness of the current incident management*.
Investigation and forensics are vital parts of the response, providing details about the incident, but early detection and response enable those investigations to be more effective and limit the scope they need to cover.
Concept tested: Incident management priorities
Source: https://learn.microsoft.com/en-us/security/operations/incident-response-process
Topics
Community Discussion
No community discussion yet for this question.