exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 216 discussion

Actual exam question from CompTIA's CS0-002
Question #: 216
Topic #: 1
[All CS0-002 Questions]

A company recently hired a new SOC provider and implemented new incident response procedures. Which of the following conjoined approaches would MOST likely be used to evaluate the new implementations for monitoring and incident response at the same time? (Choose two.)

  • A. Blue-team exercise
  • B. Disaster recovery exercise
  • C. Red-team exercise
  • D. Gray-box penetration test
  • E. Tabletop exercise
  • F. Risk assessment
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
db97
Highly Voted 2 years, 4 months ago
Selected Answer: AE
Monitoring = Blue Team Incident Response = Tabletop Exercise
upvoted 7 times
...
trojan123
Highly Voted 2 years, 5 months ago
Selected Answer: AE
A blue-team exercise is a simulation of an attack that is used to test the incident response procedures and monitoring capabilities of an organization. It is conducted by the organization's own security personnel, known as the "blue team," to evaluate their ability to detect and respond to a simulated attack. A tabletop exercise is a discussion-based simulation that is used to evaluate the incident response procedures of an organization. It is usually conducted with a small group of key personnel, such as incident responders and management, to evaluate their ability to respond to a simulated incident.
upvoted 5 times
...
FarhadFaiz
Most Recent 1 year, 7 months ago
Selected Answer: DE
Gray-box penetration test (D) will trigger the alerts for the SOC team Tabletop Exercise (E) - Will be used to see if the current IR policies in place have in gaps and whether the SOC team is able to respond accordingly.
upvoted 1 times
...
karpal
2 years ago
Selected Answer: AC
I believe is A (Blue-Team Exercise) and C (Red-team exercise) as these are usually done together - the Read team is attacking and the Blue Team is protecting. The key words in the questions are: " conjoined approaches" and "at the same time"
upvoted 2 times
karpal
2 years ago
I discussed with ChatGPT a bit. First it recomended A and E, then I told it about A and C and finally he replied: "Apologies for the confusion in my previous response. Given the options provided, the two conjoined approaches that would MOST likely be used to evaluate the new implementations for monitoring and incident response at the same time are: A. Blue-team exercise C. Red-team exercise
upvoted 1 times
...
...
kiduuu
2 years, 2 months ago
Selected Answer: AE
A. Blue-team exercise: A blue team exercise is a simulated attack designed to test and evaluate the effectiveness of an organization's security operations center (SOC) and incident response procedures. During a blue team exercise, the SOC team will attempt to detect and respond to a simulated attack in real-time, allowing the organization to evaluate its ability to detect and respond to threats effectively. E. Tabletop exercise: A tabletop exercise is a simulation of a real-world scenario that is designed to test an organization's incident response plan. During a tabletop exercise, the SOC team will work through a simulated attack scenario and evaluate the effectiveness of the incident response plan and the procedures in place to detect, respond, and mitigate the threat.
upvoted 2 times
...
knister
2 years, 4 months ago
Selected Answer: CE
A blue team exercise would not trigger IR plans.
upvoted 1 times
...
encxorblood
2 years, 4 months ago
Selected Answer: AE
A. Blue-team exercise and E. Tabletop exercise would most likely be used to evaluate the new implementations for monitoring and incident response at the same time. A blue-team exercise involves testing the effectiveness of the organization's security measures and monitoring capabilities by simulating an attack scenario. This exercise can help to identify weaknesses in the security measures and monitoring capabilities, and provide an opportunity to improve the incident response procedures. A tabletop exercise, on the other hand, is a more focused exercise that involves simulating a specific incident and walking through the steps of the incident response procedures. This exercise can help to identify any gaps in the incident response procedures and provide an opportunity to make improvements.
upvoted 4 times
2Fish
2 years, 3 months ago
Agree.. I was not sure at first, but this makes sense, and the other options just don't look right at this point.
upvoted 1 times
...
...
CatoFong
2 years, 4 months ago
Selected Answer: AE
agree with trojan and bob. blue-team exercise + tabletop
upvoted 1 times
...
bob12356
2 years, 6 months ago
Selected Answer: AE
A blue-team exercise and a tabletop exercise would be the best conjoined approaches for evaluating the new implementations for monitoring and incident response at the same time. Here is the thought process... A blue-team exercise involves simulating a cyberattack on the company's network and defenses, and then evaluating the effectiveness of the company's incident response procedures and overall security posture. A tabletop exercise involves conducting a walkthrough of the incident response procedures with the relevant stakeholders, and then discussing and evaluating the procedures and identifying any potential gaps or improvements. These two approaches would allow the company to assess the effectiveness of its new SOC provider and incident response procedures in a controlled and collaborative environment.
upvoted 3 times
...
mrodmv
2 years, 6 months ago
Selected Answer: AC
Red and blue teams for sure.
upvoted 2 times
...
DynamicTech
2 years, 6 months ago
What gray-box pen got to do with the answer? AC is the answer
upvoted 1 times
...
prntscrn23
2 years, 7 months ago
Selected Answer: CE
Will choose CE. C - This will trigger the newly implemented IR procedure E - This will test the newly IR procedure. In the Lesson Learned phase will evaluate what processes worked and did not work and if there are any enough monitoring that needs to be added or excluded.
upvoted 2 times
...
forest111
2 years, 7 months ago
Selected Answer: AC
gray-box penetration testing has nothing to do with incident response
upvoted 2 times
...
Comptia_Secret_Service
2 years, 7 months ago
Selected Answer: AC
AC most likely.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...