nerdexam
CompTIA

SY0-301 · Question #468

A security analyst informs the Chief Executive Officer (CEO) that a security breach has just occurred. This results in the Risk Manager and Chief Information Officer (CIO) being caught unaware when…

The correct answer is D. Incident management. Incident management defines the communication procedures and escalation paths that ensure all relevant stakeholders are notified promptly when a security incident occurs.

Security operations

Question

A security analyst informs the Chief Executive Officer (CEO) that a security breach has just occurred. This results in the Risk Manager and Chief Information Officer (CIO) being caught unaware when the CEO asks for further information. Which of the following strategies should be implemented to ensure the Risk Manager and CIO are not caught unaware in the future?

Options

  • AProcedure and policy management
  • BChain of custody management
  • CChange management
  • DIncident management

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • D
    89% (25)

Why each option

Incident management defines the communication procedures and escalation paths that ensure all relevant stakeholders are notified promptly when a security incident occurs.

AProcedure and policy management

Procedure and policy management governs the creation and maintenance of organizational policies and procedures but does not specifically define the real-time communication and escalation workflows triggered during a security incident.

BChain of custody management

Chain of custody management is a forensic process for tracking and preserving evidence integrity during an investigation, not a stakeholder notification and escalation strategy.

CChange management

Change management controls the process for making modifications to IT systems in a controlled manner and is unrelated to incident notification and escalation.

DIncident managementCorrect

Incident management is the structured process for detecting, reporting, coordinating, and resolving security incidents, and it includes defined notification and escalation procedures. Implementing a formal incident management plan ensures that key stakeholders such as the Risk Manager and CIO are included in the communication chain from the moment an incident is detected, preventing senior leaders from being uninformed when questioned by the CEO.

Concept tested: Incident management communication and escalation procedures

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident management#incident response#escalation#communication

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice