exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 153 discussion

Actual exam question from CompTIA's CS0-002
Question #: 153
Topic #: 1
[All CS0-002 Questions]

A security team has begun updating the risk management plan, incident response plan, and system security plan to ensure compliance with security review guidelines. Which of the following can be executed by internal managers to simulate and validate the proposed changes?

  • A. Internal management review
  • B. Control assessment
  • C. Tabletop exercise
  • D. Peer review
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
10cccordrazine
Highly Voted 2 years, 3 months ago
Selected Answer: A
"Which of the following can be executed by internal managers" Internal managers will never execute a tabletop exercise, they wouldn't have the required skills. That's for the security team to do. Now, if by that sentence they mean that the internal managers plan the session, then it could be C, but I'm still banking on A. As usual unfortunate wording which adds artificial difficulty to an otherwise simple question
upvoted 10 times
HereToStudy
2 years, 1 month ago
internal managers can execute tabletop exercises. Tabletop exercises are a common tool used by organizations to test and validate their incident response plans and security procedures. They typically involve a group of stakeholders, including internal managers and employees, who simulate a security incident or breach scenario and discuss the appropriate response actions.
upvoted 1 times
...
...
POWNED
Highly Voted 1 year, 9 months ago
Selected Answer: C
Key word here in the question is SIMULATE answer is C
upvoted 6 times
...
RobV
Most Recent 1 year, 5 months ago
Selected Answer: C
C. Tabletop exercise - Key word is "SIMULATE" A tabletop exercise is a type of simulation where key personnel gather to discuss and simulate a hypothetical scenario, often involving a cybersecurity incident. It is used to validate and test the effectiveness of plans, procedures, and communication channels. In this case, a tabletop exercise would be suitable for simulating and validating the proposed changes to the risk management plan, incident response plan, and system security plan. While internal management review (Option A) and peer review (Option D) involve evaluations by internal stakeholders, they may not actively simulate scenarios and test the plans in the same way a tabletop exercise does.
upvoted 1 times
...
Pavel019846457
1 year, 6 months ago
Selected Answer: C
I would go with "C" because of word "simulate"
upvoted 2 times
...
Nixon333
1 year, 9 months ago
Internal management review could involve high-level overview and approval but may not simulate and validate the proposed changes in a practical manner like a tabletop exercise.
upvoted 1 times
...
kyky
1 year, 11 months ago
Selected Answer: C
A tabletop exercise is a simulated scenario-based discussion that involves key stakeholders and decision-makers to evaluate the effectiveness and readiness of a proposed plan or process. In the context of security updates and compliance, a tabletop exercise can be used to simulate various security incidents and assess how the proposed changes in the risk management plan, incident response plan, and system security plan hold up in practice. It allows internal managers to test the effectiveness of the proposed changes, identify any gaps or weaknesses, and make necessary adjustments before implementing them in real-world situations.
upvoted 2 times
...
JoshuaXIV
2 years, 1 month ago
Selected Answer: C
Internal Managers can do Tabletop Exercise.
upvoted 1 times
...
HereToStudy
2 years, 1 month ago
Selected Answer: C
Internal management review is a process where internal managers review documents or processes to ensure that they comply with established policies, standards, and procedures. It is a general process that can be used for any document or process and may not be specific to validating security changes.
upvoted 1 times
...
AbusedInk
2 years, 2 months ago
Selected Answer: C
Tabletop exercises (TTXs) may or may not happen at a tabletop, but they do not involve a technical control infrastructure. TTXs can happen at the executive level (for example, CEO, CIO, or CFO), at the team level (for example, security operations center or SOC), or anywhere in between. The idea is usually to test out procedures and ensure that they actually do what they’re intended to and that everyone knows their role in responding to an event. TTXs require relatively few resources apart from deliberate planning by qualified individuals and the undisturbed time and attention of the participants.
upvoted 1 times
...
Lukers
2 years, 2 months ago
Selected Answer: C
The question is asking which would simulate and validate the proposed changes. The only answer that includes a simulation is C. Tabletop exercise.
upvoted 2 times
...
2Fish
2 years, 2 months ago
Selected Answer: C
C. Mainly because the word simulate is mentioned. I would also say that there are managers in the table top discussions along with technical staff.
upvoted 3 times
...
jleonard_ddc
2 years, 2 months ago
Selected Answer: A
An internal management review is usually done for auditing purposes to check that plans are compliant with company policies. WRONG ANSWERS • B – We’re not looking to assess if certain controls are in place or designed correctly. We’re looking to see if the plans we’ve updated are still in compliance with guidelines. • C – a tabletop exercise is verbally simulated and therefore doesn’t require extensive technical skill. However, it does require very technical knowledge, and would be done by a cybersecurity expert. • D – peers not only might not know if our policies are compliant, they may not be the best people to share security plans with.
upvoted 3 times
...
Study4America
2 years, 6 months ago
Selected Answer: C
the key word is simulate
upvoted 3 times
...
Maniact165
2 years, 6 months ago
Selected Answer: C
C right?
upvoted 1 times
...
SolventCourseisSCAM
2 years, 7 months ago
Selected Answer: A
Management review is the routine evaluation of whether management systems are performing as intended and producing the desired results as efficiently as possible. It is the ongoing “due diligence” review by management that fills the gap between day-to-day work activities and periodic formal audits.
upvoted 2 times
SolventCourseisSCAM
2 years, 6 months ago
I changed my mind to answer C, made a search on it and comptia asking here tabletop by mentioning simulation
upvoted 2 times
...
...
R00ted
2 years, 7 months ago
Selected Answer: C
C is the correct answer
upvoted 1 times
...
KingDeeko
2 years, 7 months ago
Selected Answer: A
can be executed by internal managers to simulate and validate the proposed changes? is literally has the answer in the question.. its a review.. who knows how they conduct the review. could be a simulated event
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...