nerdexam
(ISC)2

CISSP · Question #1038

What is the PRIMARY benefit of incident reporting and computer crime investigations?

The correct answer is B. Repairing the damage and preventing future occurrences. The primary benefit of incident reporting and computer crime investigations is to restore normal operations and implement lessons learned to prevent recurrence. While other outcomes may result from investigations, the core organizational goal is remediation and future prevention.

Submitted by daniela_cl· Mar 5, 2026Security Operations

Question

What is the PRIMARY benefit of incident reporting and computer crime investigations?

Options

  • AProviding evidence to law enforcement
  • BRepairing the damage and preventing future occurrences
  • CAppointing a computer emergency response team
  • DComplying with security policy

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    89% (31)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The primary benefit of incident reporting and computer crime investigations is to restore normal operations and implement lessons learned to prevent recurrence. While other outcomes may result from investigations, the core organizational goal is remediation and future prevention.

AProviding evidence to law enforcement

Providing evidence to law enforcement is a potential secondary outcome of an investigation, but it is not the primary organizational benefit, as many incidents are never prosecuted criminally.

BRepairing the damage and preventing future occurrencesCorrect

The primary purpose of incident response and computer crime investigations is to repair the damage caused by the incident and use findings to prevent similar events in the future. This aligns with the core goals of incident management frameworks like NIST SP 800-61, which emphasize containment, eradication, recovery, and post-incident lessons learned as the fundamental objectives of any investigation.

CAppointing a computer emergency response team

Appointing a computer emergency response team (CERT) is an organizational preparedness step that precedes incident response, not a benefit derived from incident reporting or investigation itself.

DComplying with security policy

Complying with security policy may be a motivation or requirement for conducting incident reporting, but it is a procedural obligation rather than the primary benefit gained from the investigation process.

Concept tested: Primary goals of incident response and investigation

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#post-incident analysis#damage control#prevention

Community Discussion

No community discussion yet for this question.

Full CISSP Practice