SY0-501 · Question #239
A director of IR is reviewing a report regarding several recent breaches. The director compiles the following statistic's - Initial IR engagement time frame - Length of time before an executive…
The correct answer is D. Tabletop exercise. To shorten incident response times based on past breach data, an organization should conduct tabletop exercises, which allow for the simulated practice and refinement of the incident response plan.
Question
A director of IR is reviewing a report regarding several recent breaches. The director compiles the following statistic's
- Initial IR engagement time frame
- Length of time before an executive management notice went out
- Average IR phase completion
The director wants to use the data to shorten the response time. Which of the following would accomplish this?
Options
- ACSIRT
- BContainment phase
- CEscalation notifications
- DTabletop exercise
How the community answered
(50 responses)- A12% (6)
- B2% (1)
- C4% (2)
- D82% (41)
Why each option
To shorten incident response times based on past breach data, an organization should conduct tabletop exercises, which allow for the simulated practice and refinement of the incident response plan.
A CSIRT (Computer Security Incident Response Team) is the group responsible for incident response, but simply having a team does not inherently provide a method for analyzing past data to proactively shorten future response times.
The containment phase is a specific stage within the incident response lifecycle, not a comprehensive method or exercise designed to analyze overall past breach statistics to improve all aspects of future response times.
Escalation notifications are a specific communication mechanism within incident response; while important, improving them alone would primarily impact executive notice times and not comprehensively address initial engagement or average phase completion times.
A tabletop exercise is a discussion-based exercise where participants verbally walk through an incident scenario to identify gaps and weaknesses in the incident response plan, communication, and decision-making processes. By proactively testing and refining the IR plan through such exercises, an organization can identify areas for improvement and implement changes that will directly lead to shorter actual incident engagement, notification, and phase completion times when real breaches occur.
Concept tested: Incident Response Plan Refinement through Exercises
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/plan-incident-response#incident-response-exercises
Topics
Community Discussion
No community discussion yet for this question.