nerdexam
Splunk

SPLK-5001 · Question #58

What is the recommended approach when handling a security incident?

The correct answer is C. Follow a pre-defined incident response plan. Following a pre-defined incident response plan (C) is correct because it ensures a systematic, coordinated response that minimizes damage, preserves evidence, and meets compliance requirements - outcomes that ad-hoc reactions cannot reliably achieve. Why the distractors fail: A…

Incident Investigation and Response

Question

What is the recommended approach when handling a security incident?

Options

  • ATake immediate actions based on intuition.
  • BIgnore the incident if it seems minor.
  • CFollow a pre-defined incident response plan.
  • DRely solely on antivirus software.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    87% (27)
  • D
    6% (2)

Explanation

Following a pre-defined incident response plan (C) is correct because it ensures a systematic, coordinated response that minimizes damage, preserves evidence, and meets compliance requirements - outcomes that ad-hoc reactions cannot reliably achieve.

Why the distractors fail:

  • A - Intuition-based actions are inconsistent and can destroy forensic evidence or escalate the incident.
  • B - "Minor" incidents are often early indicators of larger breaches; ignoring them violates due diligence and may breach legal obligations.
  • D - Antivirus handles known malware signatures but cannot coordinate containment, communication, recovery, or post-incident review.

Memory tip: Think of incident response like a fire drill - you don't improvise when the alarm sounds, you follow the rehearsed plan. The acronym PICERL (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) is the classic framework behind that plan.

Topics

#incident response plan#security incident handling#IRP#best practices

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice