exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 388 discussion

Actual exam question from Isaca's CISM
Question #: 388
Topic #: 1
[All CISM Questions]

A post-incident review revealed that key stakeholders took longer than acceptable to decide whether an application should be shut down following a security breach. Which of the following is management's BEST course of action to rectify this issue?

  • A. Improve incident response criteria.
  • B. Improve incident response testing.
  • C. Define incident classification.
  • D. Establish containment procedures.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 3 months ago
Selected Answer: C
C. Define incident classification. One of the key things that management can do to rectify the issue of key stakeholders taking too long to decide whether an application should be shut down following a security breach is to define incident classification. Incident classification is the process of categorizing incidents based on their severity and potential impact on the organization. By clearly defining the different levels of incidents, management can establish clear criteria for when an application should be shut down and can ensure that key stakeholders are aware of these criteria. This will help to ensure that decisions regarding application shutdowns are made quickly and effectively in the event of a security breach, which is crucial for containing the damage and minimizing the impact of the incident.
upvoted 13 times
...
SHERLOCKAWS
Most Recent 3 weeks, 1 day ago
Selected Answer: A
This is A. Improve incident response criteria. If stakeholders are stuck debating instead of acting, the criteria weren’t clear or actionable enough. The issue here is delayed decision making none of the other answers are helping on this.
upvoted 1 times
...
Agamennore
8 months, 1 week ago
Selected Answer: D
IMHO is D, it’s required a different containment provedure
upvoted 2 times
...
Bl1024
8 months, 1 week ago
Selected Answer: D
The more accurate response would be D. They could not decide ifvthe app should be shutdown, that sould be defined in the containment prosedure, leaving no room for debate.
upvoted 2 times
...
[Removed]
9 months ago
Selected Answer: A
Shit question. Literally both A and C are defined in the official textbook as something that could be right. A. Improve incident response criteria: The Manual notes that clear criteria for classifying and escalating incidents is vital for effective incident response (Domain 3, p. 122). C. Define incident classification: Incident classification is part of incident response planning and can help in quicker decision-making (Domain 3, p. 122). That being said... It say classification CAN help not that it WILL help, whereas it's feelings toward response criteria is more definitive.
upvoted 4 times
...
richck102
10 months, 3 weeks ago
D. Establish containment procedures.
upvoted 3 times
richck102
10 months, 3 weeks ago
or .....A. Improve incident response criteria.
upvoted 1 times
...
...
Saisharan
11 months, 1 week ago
Most incidents require containment, so that is an important consideration early in the course of handling each incident. Containment provides time for developing a tailored remediation strategy. An essential part of containment is decision-making (e.g., shut down a system, disconnect it from a network, or disable certain functions). Such decisions are much easier to make if there are predetermined strategies and procedures for containing the incident. Organizations should define acceptable risks in dealing with incidents and develop strategies accordingly. Containment strategies vary based on the type of incident. For example, the strategy for containing an email-borne malware infection is quite different from that of a network-based DDoS attack. Organizations should create separate containment strategies for each major incident type, with criteria documented clearly to facilitate decision-making.” So the Option is D
upvoted 4 times
...
Abhey
1 year ago
Selected Answer: A
The BEST course of action for management to rectify the issue of key stakeholders taking longer than acceptable to decide whether an application should be shut down following a security breach is to improve incident response criteria. By improving the incident response criteria, the decision-making process will become clearer and more efficient, allowing key stakeholders to make quicker decisions. This can include defining the decision-making process, establishing criteria for when an application should be shut down, and providing training to stakeholders on how to make effective decisions in incident response scenarios.
upvoted 2 times
...
dark_3k03r
1 year ago
Selected Answer: A
The correct answer is (A) Improve incident response criteria, cause it is the only answer that is looking to improve the decision-making process by providing a set of criteria by which a decision can be made. With a clear process saying when containment should take place, the response process should be much faster. Rationale: B. Improve incident response testing is great, but every incident is different and without a clear guideline of how to proceed the same problem will persist. C. Define incident classification say what type of incident it is, but doesn't provide any guidance on how to do containment or when. That is what (A) is for. D. Establish containment procedures is important for containment, but this comes after (A) has been done. Thus why (A) is more important.
upvoted 3 times
...
MyKasala
1 year, 3 months ago
Why not D ?
upvoted 4 times
vavofa5697
1 year, 2 months ago
agreed. D should be the answer
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago