nerdexam
PECB

LEAD-AUDITOR · Question #8

In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:

The correct answer is D. Make the information security incident details known to all employees. The role and responsibility that system users should not observe in the event of an information security incident is D: make the information security incident details known to all employees. This is not a proper role or responsibility for system users, as it could cause unnecessa

Incident Management and Response

Question

In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:

Options

  • AReport suspected or known incidents upon discovery through the Servicedesk
  • BPreserve evidence if necessary
  • CCooperate with investigative personnel during investigation if needed
  • DMake the information security incident details known to all employees

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    12% (4)
  • D
    76% (26)

Explanation

The role and responsibility that system users should not observe in the event of an information security incident is D: make the information security incident details known to all employees. This is not a proper role or responsibility for system users, as it could cause unnecessary panic, confusion or speculation among employees who are not involved in the incident response process. It could also compromise the confidentiality and integrity of the incident information, which could be sensitive or confidential in nature. Making the information security incident details known to all employees could also violate the information security policies and procedures of the organization, which may require a certain level of discretion and confidentiality when dealing with

Topics

#incident management#roles and responsibilities#evidence preservation#security incidents

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice