nerdexam
Isaca

CRISC · Question #635

An organization becomes aware that IT security failed to detect a coordinated cyber attack on its data center. Which of the following is the BEST course of action?

The correct answer is C. Conduct a root cause analysis.. Upon discovering that IT security failed to detect a coordinated cyber attack, the most appropriate immediate action is to conduct a root cause analysis.

Submitted by omar99· Apr 18, 2026Risk Response and Reporting

Question

An organization becomes aware that IT security failed to detect a coordinated cyber attack on its data center. Which of the following is the BEST course of action?

Options

  • APerform a business impact analysis (BIA).
  • BIdentify compensating controls
  • CConduct a root cause analysis.
  • DRevise key risk indicator (KRI) thresholds.

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    71% (22)
  • D
    19% (6)

Why each option

Upon discovering that IT security failed to detect a coordinated cyber attack, the most appropriate immediate action is to conduct a root cause analysis.

APerform a business impact analysis (BIA).

Performing a business impact analysis (BIA) assesses the impact of disruptions but does not address why the attack went undetected or how to fix the security gap.

BIdentify compensating controls

Identifying compensating controls may be a part of the solution, but without understanding the root cause of the initial failure, the compensating controls might not address the core issue.

CConduct a root cause analysis.Correct

A failure to detect a coordinated cyber attack indicates a significant gap or deficiency in security controls, processes, or technologies. Conducting a root cause analysis is essential to thoroughly investigate the underlying reasons for this failure, identify systemic weaknesses, and implement effective, targeted remediation to prevent future occurrences.

DRevise key risk indicator (KRI) thresholds.

Revising key risk indicator (KRI) thresholds might be a consequence of the analysis, but it doesn't explain or fix the failure in detection itself.

Concept tested: Post-incident analysis (root cause)

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/manage/security-operations/incident-response#root-cause-analysis

Topics

#Root Cause Analysis#Incident Response#Control Failure#Cyber Attack

Community Discussion

No community discussion yet for this question.

Full CRISC Practice