GCIH · Question #198
Which of the following procedures is designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data…
The correct answer is B. Cyber Incident Response Plan. A Cyber Incident Response Plan is specifically designed to guide security personnel through identifying, mitigating, and recovering from malicious computer incidents.
Question
Which of the following procedures is designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data, denialof-service, or unauthorized changes to system hardware, software, or data?
Options
- ADisaster Recovery Plan
- BCyber Incident Response Plan
- CCrisis Communication Plan
- DOccupant Emergency Plan
How the community answered
(28 responses)- A4% (1)
- B86% (24)
- C4% (1)
- D7% (2)
Why each option
A Cyber Incident Response Plan is specifically designed to guide security personnel through identifying, mitigating, and recovering from malicious computer incidents.
A Disaster Recovery Plan focuses on restoring IT infrastructure and operations after large-scale disruptions such as natural disasters, not specifically on responding to malicious cyber incidents.
A Cyber Incident Response Plan (CIRP) is a formal, documented set of procedures that outlines how an organization detects, responds to, and recovers from cybersecurity incidents such as unauthorized access, denial-of-service attacks, and unauthorized changes to systems or data. It covers the full incident lifecycle from identification through recovery, directly matching the description in the question. This distinguishes it from other plans that address communication, physical safety, or broad infrastructure recovery.
A Crisis Communication Plan addresses how an organization communicates with stakeholders during a crisis, not the technical procedures for identifying and mitigating cyber attacks.
An Occupant Emergency Plan covers physical safety and evacuation procedures for building occupants during emergencies, and is unrelated to cybersecurity incident response.
Concept tested: Cyber Incident Response Plan definition and purpose
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.