nerdexam
(ISC)2

SSCP · Question #471

Which of the following is NOT a task normally performed by a Computer Incident Response Team (CIRT)?

The correct answer is A. Develop an information security policy.. Developing an information security policy is a governance function performed by senior management and the security department - not the CIRT. The CIRT's responsibilities are reactive and operational: responding to incidents, coordinating communication about incidents to relevant

Submitted by haruto_sh· Apr 18, 2026Incident Response and Recovery

Question

Which of the following is NOT a task normally performed by a Computer Incident Response Team (CIRT)?

Options

  • ADevelop an information security policy.
  • BCoordinate the distribution of information pertaining to the incident to the appropriate parties.
  • CMitigate risk to the enterprise.
  • DAssemble teams to investigate the potential vulnerabilities.

How the community answered

(28 responses)
  • A
    89% (25)
  • B
    4% (1)
  • D
    7% (2)

Explanation

Developing an information security policy is a governance function performed by senior management and the security department - not the CIRT. The CIRT's responsibilities are reactive and operational: responding to incidents, coordinating communication about incidents to relevant stakeholders, mitigating risk to the organization during an incident, and investigating potential vulnerabilities that were exploited. Policy development is a strategic, pre-incident administrative task that falls outside the CIRT's operational mandate.

Topics

#Incident Response#CIRT#Security Roles and Responsibilities#Security Policy

Community Discussion

No community discussion yet for this question.

Full SSCP Practice