exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 264 discussion

Actual exam question from Isaca's CISM
Question #: 264
Topic #: 1
[All CISM Questions]

An organization's operations have been significantly impacted by a cyberattack resulting in data loss. Once the attack has been contained, what should the security team do NEXT?

  • A. Update the incident response plan.
  • B. Perform a root cause analysis.
  • C. Implement compensating controls.
  • D. Conduct a lessons learned exercise.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bcffcfb
10 months, 2 weeks ago
B While implementing compensating controls (option C) is important, it typically comes after understanding the root cause of the incident. How can we implement a control unless we find out the root cause/vulnerabilities etc.
upvoted 1 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: B
B. Perform a root cause analysis: It's crucial to understand how the cyberattack occurred in the first place. A root cause analysis helps identify the vulnerabilities or weaknesses in the organization's security posture that allowed the attack to happen. This analysis informs future security improvements and helps prevent similar incidents in the future.
upvoted 3 times
...
POWNED
1 year, 5 months ago
Selected Answer: B
You need to find the root cause before lessons learned. Answer is B
upvoted 1 times
...
Uncle_Lucifer
1 year, 5 months ago
Actually Answer could be C. Your next step should be eradicate. Root cause analysis is performed post incidence fix same with lesson learned. In exam i will select C
upvoted 1 times
e891cd1
1 year, 1 month ago
The root cause analysis is done as part of the Eradication process cuz u need to know the root cause to understand how it can be eradicated.
upvoted 1 times
...
...
Uncle_Lucifer
1 year, 5 months ago
I was wrong. Answer is B. Containment is when you isolate a system to stop it from affecting or connecting to network. In this stage, the incidence hasn;t been mitigated, therefore leason learned is not valid. You need Root Cause analysis to determin what the issue is then fix/mitigate it. Answer is B. Sorry for selecting C. Admin please delete my selection.
upvoted 1 times
Uncle_Lucifer
1 year, 5 months ago
ooops i selected D not C
upvoted 2 times
...
...
Uncle_Lucifer
1 year, 5 months ago
Selected Answer: D
After incidence should be lessoned leaned. You would have performed root cause analysis to know how to solve and mitigate the issue. Answer id D
upvoted 1 times
Uncle_Lucifer
1 year, 5 months ago
I was wrong. Answer is B. Containment is when you isolate a system to stop it from affecting or connecting to network. In this stage, the incidence hasn;t been mitigated, therefore leason learned is not valid. You need Root Cause analysis to determin what the issue is then fix/mitigate it. Answer is B. Sorry for selecting C. Admin please delete my selection.
upvoted 1 times
...
...
Ej24356
1 year, 7 months ago
Why not D, isn't root cause analysis done in conjunction with lessons learned?
upvoted 2 times
...
oluchecpoint
1 year, 8 months ago
B. Perform a root cause analysis: It's crucial to understand how the cyberattack occurred in the first place. A root cause analysis helps identify the vulnerabilities or weaknesses in the organization's security posture that allowed the attack to happen. This analysis informs future security improvements and helps prevent similar incidents in the future.
upvoted 1 times
...
richck102
1 year, 11 months ago
Selected Answer: B
B. Perform a root cause analysis.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago