CISM · Question #962
Which of the following is the MOST important consideration during the recovery phase of a data breach?
The correct answer is A. Enabling system owners to declare normal operation. During the recovery phase, the primary objective is restoring systems and services to verified, normal operational status - making option A correct, as formally enabling system owners to declare normal operation marks the completion of recovery and signals a return to…
Question
Which of the following is the MOST important consideration during the recovery phase of a data breach?
Options
- AEnabling system owners to declare normal operation
- BEstablishing chain of custody when handling potential evidence
- CDeveloping criteria for when to report an incident to authorities
- DDetermining the severity of the incident and escalating as needed
How the community answered
(66 responses)- A76% (50)
- B14% (9)
- C3% (2)
- D8% (5)
Explanation
During the recovery phase, the primary objective is restoring systems and services to verified, normal operational status - making option A correct, as formally enabling system owners to declare normal operation marks the completion of recovery and signals a return to business-as-usual.
Option B (chain of custody) belongs to the containment and evidence-handling stages earlier in the incident response lifecycle, not recovery. Option C (criteria for reporting to authorities) is a preparation-phase activity that should be defined in policy before an incident occurs, not determined during recovery. Option D (determining severity and escalating) is a detection and analysis activity that happens early in the response, before recovery begins.
Memory tip: Think of recovery as "signing off" - just like a contractor finishing a job needs the homeowner to sign off that work is complete, the recovery phase ends when system owners formally confirm operations are back to normal.
Topics
Community Discussion
No community discussion yet for this question.