SPLK-5001 · Question #58
What is the recommended approach when handling a security incident?
The correct answer is C. Follow a pre-defined incident response plan. Following a pre-defined incident response plan (C) is correct because it ensures a systematic, coordinated response that minimizes damage, preserves evidence, and meets compliance requirements - outcomes that ad-hoc reactions cannot reliably achieve. Why the distractors fail: A…
Question
What is the recommended approach when handling a security incident?
Options
- ATake immediate actions based on intuition.
- BIgnore the incident if it seems minor.
- CFollow a pre-defined incident response plan.
- DRely solely on antivirus software.
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- C87% (27)
- D6% (2)
Explanation
Following a pre-defined incident response plan (C) is correct because it ensures a systematic, coordinated response that minimizes damage, preserves evidence, and meets compliance requirements - outcomes that ad-hoc reactions cannot reliably achieve.
Why the distractors fail:
- A - Intuition-based actions are inconsistent and can destroy forensic evidence or escalate the incident.
- B - "Minor" incidents are often early indicators of larger breaches; ignoring them violates due diligence and may breach legal obligations.
- D - Antivirus handles known malware signatures but cannot coordinate containment, communication, recovery, or post-incident review.
Memory tip: Think of incident response like a fire drill - you don't improvise when the alarm sounds, you follow the rehearsed plan. The acronym PICERL (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) is the classic framework behind that plan.
Topics
Community Discussion
No community discussion yet for this question.