CISM · Question #939
Which of the following is MOST important for responding effectively to security breaches?
The correct answer is A. Incident classification. Incident classification is the critical first step because it determines the entire response strategy - severity level, who gets notified, what resources are deployed, and how urgently. Without knowing what kind of breach you're dealing with, every subsequent action lacks…
Question
Which of the following is MOST important for responding effectively to security breaches?
Options
- AIncident classification
- BCommunication plan
- CChain of custody
- DLog monitoring
How the community answered
(27 responses)- A56% (15)
- B11% (3)
- C26% (7)
- D7% (2)
Explanation
Incident classification is the critical first step because it determines the entire response strategy - severity level, who gets notified, what resources are deployed, and how urgently. Without knowing what kind of breach you're dealing with, every subsequent action lacks direction and priority.
Why the others fall short:
- B. Communication plan - Valuable, but you can only communicate effectively after classification tells you what happened and how serious it is. Communication is downstream of classification.
- C. Chain of custody - Essential for forensic evidence and legal proceedings, but it's a post-identification concern focused on preserving evidence, not driving the initial response.
- D. Log monitoring - A detective control used to detect incidents before or during them; it precedes incident response rather than defining how you respond once a breach is confirmed.
Memory tip: Think of the ER triage analogy - paramedics classify patient severity before treatment begins. In incident response, classification is your triage: it tells you whether you're dealing with a scraped knee or a cardiac arrest, and everything else follows from that answer.
Topics
Community Discussion
No community discussion yet for this question.