nerdexam
PECB

LEAD-AUDITOR · Question #340

Drag and Drop Question Your organisation is currently seeking ISO/IEC27001:2022 certification. You have just qualified as an Internal ISMS auditor and the ICT Manager wants to use your newly acquired

Sign in or unlock LEAD-AUDITOR to reveal the answer and full explanation for question #340. The question stem and answer options stay visible for context.

Information Security Incident Management

Question

Drag and Drop Question Your organisation is currently seeking ISO/IEC27001:2022 certification. You have just qualified as an Internal ISMS auditor and the ICT Manager wants to use your newly acquired knowledge to assist him with the design of an information security incident management process. He identifies the following stages in his planned process and asks you to confirm which order they should appear in. Answer:

Exhibit

LEAD-AUDITOR question #340 exhibit

Answer Area

Drag items

Incident identification - identify the incident and confirm it is a genuine incidentRisk assessment - assess the impact of the incident to prioritize resolutionIncident containment - contain the incident to limit further damageInvestigation and root cause analysis - understand why the incident occurred to prevent recurrenceIncident eradication - remove the cause of the incident and restore systems to normal operationRecovery - restore systems and data from backups or alternative sources if neededPost-incident review - analyze the incident response process for lessons learned

Unlock LEAD-AUDITOR to see the answer

You've previewed enough free LEAD-AUDITOR questions. Unlock LEAD-AUDITOR for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#incident management#incident response process#ISO 27001#ISMS incident handling
Full LEAD-AUDITOR Practice