nerdexam
CompTIA

SY0-701 · Question #637

A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email…

The correct answer is B. IRP. An Incident Response Plan (IRP) is the document specifically designed to guide an organization through detecting, containing, eradicating, and recovering from security incidents - exactly the detective and corrective activities described for threats like phishing and business…

Submitted by viktor_hu· Mar 6, 2026Security program management and oversight

Question

A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?

Options

  • ASDLC
  • BIRP
  • CBCP
  • DAUP

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    74% (29)
  • C
    5% (2)
  • D
    8% (3)

Explanation

An Incident Response Plan (IRP) is the document specifically designed to guide an organization through detecting, containing, eradicating, and recovering from security incidents - exactly the detective and corrective activities described for threats like phishing and business email compromise. The SDLC (Software Development Life Cycle) governs how software is built and maintained, making it irrelevant to threat response procedures. A BCP (Business Continuity Plan) focuses on keeping operations running during major disruptions, not on responding to specific attack vectors. An AUP (Acceptable Use Policy) sets rules for how employees may use company resources - it's a preventive control, not detective or corrective.

Memory tip: Think of the IRP as the organization's "playbook for when bad things happen." Phishing, social engineering, and BEC are all incidents - so the Incident Response Plan is where you look.

Topics

#Incident Response#Security Policies#Threat Management#CISO Responsibilities

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice