SY0-701 · Question #637
A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email…
The correct answer is B. IRP. An Incident Response Plan (IRP) is the document specifically designed to guide an organization through detecting, containing, eradicating, and recovering from security incidents - exactly the detective and corrective activities described for threats like phishing and business…
Question
A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?
Options
- ASDLC
- BIRP
- CBCP
- DAUP
How the community answered
(39 responses)- A13% (5)
- B74% (29)
- C5% (2)
- D8% (3)
Explanation
An Incident Response Plan (IRP) is the document specifically designed to guide an organization through detecting, containing, eradicating, and recovering from security incidents - exactly the detective and corrective activities described for threats like phishing and business email compromise. The SDLC (Software Development Life Cycle) governs how software is built and maintained, making it irrelevant to threat response procedures. A BCP (Business Continuity Plan) focuses on keeping operations running during major disruptions, not on responding to specific attack vectors. An AUP (Acceptable Use Policy) sets rules for how employees may use company resources - it's a preventive control, not detective or corrective.
Memory tip: Think of the IRP as the organization's "playbook for when bad things happen." Phishing, social engineering, and BEC are all incidents - so the Incident Response Plan is where you look.
Topics
Community Discussion
No community discussion yet for this question.