nerdexam
CompTIA

SY0-301 · Question #283

Which of the following is BEST carried out immediately after a security breach is discovered?

The correct answer is D. Incident management. Incident management is the structured process for responding to a security breach - it includes containment, eradication, recovery, and lessons learned. It is the first and most critical action immediately after a breach is discovered because it coordinates the entire response…

Security operations

Question

Which of the following is BEST carried out immediately after a security breach is discovered?

Options

  • ARisk transference
  • BAccess control revalidation
  • CChange management
  • DIncident management

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    89% (32)

Explanation

Incident management is the structured process for responding to a security breach - it includes containment, eradication, recovery, and lessons learned. It is the first and most critical action immediately after a breach is discovered because it coordinates the entire response. Risk transference (A) is a long-term risk strategy (e.g., purchasing insurance) done before breaches. Access control revalidation (B) may be part of the recovery phase but is not the first step. Change management (C) governs planned system changes and is not an incident response activity.

Topics

#incident response#incident management#security breach#security operations

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice