Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISSP topic 1 question 423 discussion

Actual exam question from ISC's CISSP
Question #: 423
Topic #: 1
[All CISSP Questions]

Which is the FIRST action the Incident Response team should take when an incident is suspected?

  • A. Choose a containment strategy.
  • B. Record all facts regarding the incident.
  • C. Attempt to identify the attacker.
  • D. Notify management of the incident.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Amit3
3 weeks ago
Answer is B. The Incident is suspected and IR Team is engaged, which mean its major and next step would be Response, which is not the choice here. Then Mitigate (or Containment Strategy), which is B.
upvoted 1 times
...
eboehm
1 month ago
Selected Answer: A
haha soo many people blindly picking B and not reading the question. Its NOT b and its NOT validate the incident. If the IR team has been activated, its already been decided that its an incident. Incident Response is Detect --> response --> mitgate(contain) --> report --> remediate --> etc
upvoted 1 times
...
Hongjun
1 month, 1 week ago
Selected Answer: B
First B then D. they are belongs to respons stage . next stage- Mitigation which is A.
upvoted 1 times
...
Soleandheel
4 months, 3 weeks ago
B. Record all facts regarding the incident. When the incident is suspected, you want to record all facts to help confirm if it becomes and actual incident. Once it becomes confirmed as an actual incident then containment is the next course of action.
upvoted 3 times
...
HughJassole
11 months ago
B seems a bit off because of the "record all facts", it should say "record all known facts". So it almost seems like it would be at the end when you know "all" facts. When you get an incident call you log it in the ticketing system first, so that's the start. I did some research and verified, step 2 "Detection & Analysis" states "ncident documentation: If the signal proves valid, the IR team must begin documenting all facts in relation to the incident and continue logging all actions taken throughout the process." Containment is step #3. https://www.crowdstrike.com/cybersecurity-101/incident-response/incident-response-steps/
upvoted 1 times
...
Watcher009
1 year ago
Selected Answer: B
First step is to validate the incident
upvoted 1 times
jackdryan
12 months ago
B is correct
upvoted 1 times
...
...
DASH_v
1 year ago
B. An incident response team that suspects that an incident has occurred should immediately start recording all facts regarding the incident. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
upvoted 2 times
...
[Removed]
1 year, 1 month ago
Selected Answer: B
The incident is suspected. It needs confirmation (B), and no action yet (C).
upvoted 3 times
...
emrys
1 year, 1 month ago
Selected Answer: A
Containment is the first priority when responding to an incident. The incident response team must act quickly to contain incident, limit the damage and prevent further spread. After the incident is contained, the team can begin to gather information and assess the situation. They can then identify the attacker, record all facts, and notify management as appropriate. But the immediate priority is to contain the incident.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...