CompTIA CySA+ CS0-003 Preparation And Post-Incident Activities Practice Test

 

Objective 3.3 • 40 original questions

This CompTIA CySA+ CS0-003 practice test focuses on objective 3.3: preparation and post-incident activities. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.

Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.

Question 1

At Woodgrove Bank, a threat hunter has two simultaneous requirements: establish who does what and who can make decisions during an incident, and improve responder readiness before a real incident occurs. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Forensic analysis
  2. Responder training
  3. Incident-response tools
  4. Incident response plan
  5. Tabletop exercise

Correct answers: B, D

Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs. An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

Option review:

A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

B: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

Learning point: Use Incident response plan, Responder training when the key requirement is to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

Question 2

A ticket at Humongous Insurance asks a risk analyst to ensure responders have tested investigation and containment tooling before an incident. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.

  1. Business continuity and disaster recovery alignment
  2. Tabletop exercise
  3. Incident-response tools
  4. Responder training
  5. Forensic analysis

Correct answer: C

Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.

Question 3

Contoso Health is designing a combined control. It must standardize response steps for a common incident such as phishing or ransomware, and conduct deeper technical examination after containment to understand the intrusion. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. Playbooks
  2. Root cause analysis
  3. Tabletop exercise
  4. Forensic analysis
  5. Lessons learned

Correct answers: A, D

Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware. Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Option review:

A: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

Learning point: Use Playbooks, Forensic analysis when the key requirement is to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

Question 4

A review at Blue Yonder Airlines finds a gap: the team cannot reliably test the response plan through a discussion-based simulated incident. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Responder training
  2. Playbooks
  3. Tabletop exercise
  4. Root cause analysis
  5. Incident response plan

Correct answer: C

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

Option review:

A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

D: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.

Question 5

a detection engineer at Lucerne Publishing is comparing several approaches. The deciding requirement is to improve responder readiness before a real incident occurs. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.

  1. Business continuity and disaster recovery alignment
  2. Playbooks
  3. Lessons learned
  4. Incident-response tools
  5. Responder training

Correct answer: E

Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

C: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

D: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

E: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.

Question 6

While supporting an online banking environment, a vulnerability analyst is asked to coordinate cyber response with continuity and recovery of critical services. Which concept or tool is the clearest match? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Business continuity and disaster recovery alignment
  2. Incident response plan
  3. Playbooks
  4. Root cause analysis
  5. Responder training

Correct answer: A

Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

B: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

D: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

Learning point: Use Business continuity and disaster recovery alignment when the key requirement is to coordinate cyber response with continuity and recovery of critical services.

Question 7

A new security procedure at City Power Utilities must enable analysts to conduct deeper technical examination after containment to understand the intrusion. Which option is the BEST choice? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Forensic analysis
  2. Incident-response tools
  3. Business continuity and disaster recovery alignment
  4. Tabletop exercise
  5. Lessons learned

Correct answer: A

Why: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Option review:

A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

Learning point: Use Forensic analysis when the key requirement is to conduct deeper technical examination after containment to understand the intrusion.

Question 8

The primary objective for A. Datum Logistics is to determine why the incident became possible rather than only what happened. Which selection best satisfies that objective in a newly acquired subsidiary? The team wants the most defensible analyst action before expanding the investigation.

  1. Root cause analysis
  2. Tabletop exercise
  3. Business continuity and disaster recovery alignment
  4. Incident response plan
  5. Forensic analysis

Correct answer: A

Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

Option review:

A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.

Question 9

At Northwind Traders, a security engineer has two simultaneous requirements: turn incident experience into prioritized process and control improvements, and test the response plan through a discussion-based simulated incident. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Tabletop exercise
  2. Lessons learned
  3. Incident-response tools
  4. Incident response plan
  5. Forensic analysis

Correct answers: A, B

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident. A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

Option review:

A: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

Learning point: Use Lessons learned, Tabletop exercise when the key requirement is to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

Question 10

During an investigation at Alpine Ski House, the immediate requirement is to establish who does what and who can make decisions during an incident. What should a cloud security analyst select? Assume the activity is authorized and must follow normal enterprise change control.

  1. Playbooks
  2. Lessons learned
  3. Root cause analysis
  4. Incident response plan
  5. Responder training

Correct answer: D

Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

Option review:

A: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

Learning point: Use Incident response plan when the key requirement is to establish who does what and who can make decisions during an incident.

Question 11

Coho Winery is updating its security operations standard for a branch-office network. Which option most directly helps the team ensure responders have tested investigation and containment tooling before an incident? Assume no additional product-specific features are available beyond the concepts listed.

  1. Forensic analysis
  2. Incident-response tools
  3. Responder training
  4. Incident response plan
  5. Tabletop exercise

Correct answer: B

Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

Option review:

A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.

Question 12

A ticket at Litware Manufacturing asks an incident responder to standardize response steps for a common incident such as phishing or ransomware. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Forensic analysis
  2. Responder training
  3. Business continuity and disaster recovery alignment
  4. Playbooks
  5. Tabletop exercise

Correct answer: D

Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

Option review:

A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

B: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

Learning point: Use Playbooks when the key requirement is to standardize response steps for a common incident such as phishing or ransomware.

Question 13

In a multi-site enterprise, a security administrator must test the response plan through a discussion-based simulated incident. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.

  1. Forensic analysis
  2. Responder training
  3. Root cause analysis
  4. Tabletop exercise
  5. Incident response plan

Correct answer: D

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

Option review:

A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

B: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.

Question 14

A review at Consolidated Messenger finds a gap: the team cannot reliably improve responder readiness before a real incident occurs. Which option best closes that gap? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Responder training
  2. Lessons learned
  3. Incident response plan
  4. Incident-response tools
  5. Tabletop exercise

Correct answer: A

Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Option review:

A: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

D: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.

Question 15

Adventure Works is designing a combined control. It must coordinate cyber response with continuity and recovery of critical services, and establish who does what and who can make decisions during an incident. Which TWO options are most appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Business continuity and disaster recovery alignment
  2. Incident response plan
  3. Playbooks
  4. Responder training
  5. Incident-response tools

Correct answers: A, B

Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services. An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

B: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.

E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.

Learning point: Use Business continuity and disaster recovery alignment, Incident response plan when the key requirement is to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.

Question 16

During a security review, an incident coordinator must address two separate needs: conduct deeper technical examination after containment to understand the intrusion, and ensure responders have tested investigation and containment tooling before an incident. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Root cause analysis
  2. Incident-response tools
  3. Incident response plan
  4. Business continuity and disaster recovery alignment
  5. Forensic analysis

Correct answers: B, E

Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident. Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Option review:

A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.

B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.

D: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Learning point: Use Forensic analysis, Incident-response tools when the key requirement is to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.

Question 17

A new security procedure at Datum Fabrication must enable analysts to determine why the incident became possible rather than only what happened. Which option is the BEST choice? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Root cause analysis
  2. Incident response plan
  3. Responder training
  4. Playbooks
  5. Lessons learned

Correct answer: A

Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

Option review:

A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

B: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.

Question 18

The primary objective for Tailspin Toys is to turn incident experience into prioritized process and control improvements. Which selection best satisfies that objective in an e-commerce platform? Assume the activity is authorized and must follow normal enterprise change control.

  1. Responder training
  2. Lessons learned
  3. Forensic analysis
  4. Playbooks
  5. Root cause analysis

Correct answer: B

Why: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

Option review:

A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

C: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

Learning point: Use Lessons learned when the key requirement is to turn incident experience into prioritized process and control improvements.

Question 19

At Proseware Research, a malware analyst needs to establish who does what and who can make decisions during an incident. Which option is the BEST fit for a restricted research segment? Assume no additional product-specific features are available beyond the concepts listed.

  1. Incident-response tools
  2. Lessons learned
  3. Root cause analysis
  4. Forensic analysis
  5. Incident response plan

Correct answer: E

Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

Option review:

A: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

Learning point: Use Incident response plan when the key requirement is to establish who does what and who can make decisions during an incident.

Question 20

During a security review, a SOC analyst must address two separate needs: ensure responders have tested investigation and containment tooling before an incident, and coordinate cyber response with continuity and recovery of critical services. Select TWO. The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Responder training
  2. Business continuity and disaster recovery alignment
  3. Incident-response tools
  4. Lessons learned
  5. Playbooks

Correct answers: B, C

Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services. Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

Option review:

A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.

B: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

D: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.

E: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.

Learning point: Use Incident-response tools, Business continuity and disaster recovery alignment when the key requirement is to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.

Question 21

Woodgrove Bank is updating its security operations standard for a high-value payment environment. Which option most directly helps the team standardize response steps for a common incident such as phishing or ransomware? Base the decision on the primary security requirement, not on implementation convenience.

  1. Business continuity and disaster recovery alignment
  2. Playbooks
  3. Responder training
  4. Incident response plan
  5. Forensic analysis

Correct answer: B

Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

Learning point: Use Playbooks when the key requirement is to standardize response steps for a common incident such as phishing or ransomware.

Question 22

A ticket at Humongous Insurance asks a risk analyst to test the response plan through a discussion-based simulated incident. Which choice addresses the requirement most directly? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Business continuity and disaster recovery alignment
  2. Root cause analysis
  3. Tabletop exercise
  4. Forensic analysis
  5. Responder training

Correct answer: C

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.

Question 23

In a hospital network, a SOC analyst must improve responder readiness before a real incident occurs. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Root cause analysis
  2. Tabletop exercise
  3. Incident response plan
  4. Business continuity and disaster recovery alignment
  5. Responder training

Correct answer: E

Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Option review:

A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

D: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

E: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.

Question 24

A review at Blue Yonder Airlines finds a gap: the team cannot reliably coordinate cyber response with continuity and recovery of critical services. Which option best closes that gap? The team wants the most defensible analyst action before expanding the investigation.

  1. Business continuity and disaster recovery alignment
  2. Lessons learned
  3. Tabletop exercise
  4. Incident response plan
  5. Forensic analysis

Correct answer: A

Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.

Learning point: Use Business continuity and disaster recovery alignment when the key requirement is to coordinate cyber response with continuity and recovery of critical services.

Question 25

a detection engineer at Lucerne Publishing is comparing several approaches. The deciding requirement is to conduct deeper technical examination after containment to understand the intrusion. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Playbooks
  2. Root cause analysis
  3. Forensic analysis
  4. Responder training
  5. Incident response plan

Correct answer: C

Why: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Option review:

A: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

C: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

Learning point: Use Forensic analysis when the key requirement is to conduct deeper technical examination after containment to understand the intrusion.

Question 26

While supporting an online banking environment, a vulnerability analyst is asked to determine why the incident became possible rather than only what happened. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.

  1. Incident-response tools
  2. Root cause analysis
  3. Incident response plan
  4. Tabletop exercise
  5. Business continuity and disaster recovery alignment

Correct answer: B

Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

Option review:

A: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

E: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.

Question 27

City Power Utilities is designing a combined control. It must turn incident experience into prioritized process and control improvements, and test the response plan through a discussion-based simulated incident. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. Responder training
  2. Tabletop exercise
  3. Forensic analysis
  4. Lessons learned
  5. Root cause analysis

Correct answers: B, D

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident. A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

Option review:

A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

C: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

D: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

Learning point: Use Lessons learned, Tabletop exercise when the key requirement is to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.

Question 28

During a security review, a security consultant must address two separate needs: establish who does what and who can make decisions during an incident, and improve responder readiness before a real incident occurs. Select TWO. The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Business continuity and disaster recovery alignment
  2. Playbooks
  3. Incident response plan
  4. Responder training
  5. Incident-response tools

Correct answers: C, D

Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident. Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

Learning point: Use Incident response plan, Responder training when the key requirement is to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.

Question 29

At Northwind Traders, a security engineer needs to ensure responders have tested investigation and containment tooling before an incident. Which option is the BEST fit for a regional distribution network? Base the decision on the primary security requirement, not on implementation convenience.

  1. Incident response plan
  2. Playbooks
  3. Business continuity and disaster recovery alignment
  4. Lessons learned
  5. Incident-response tools

Correct answer: E

Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

Option review:

A: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

D: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.

Question 30

For a SaaS-heavy business, the team must accomplish both of these goals: standardize response steps for a common incident such as phishing or ransomware, and conduct deeper technical examination after containment to understand the intrusion. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Lessons learned
  2. Tabletop exercise
  3. Playbooks
  4. Responder training
  5. Forensic analysis

Correct answers: C, E

Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware. Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Option review:

A: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Learning point: Use Playbooks, Forensic analysis when the key requirement is to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.

Question 31

Coho Winery is updating its security operations standard for a branch-office network. Which option most directly helps the team test the response plan through a discussion-based simulated incident? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Lessons learned
  2. Forensic analysis
  3. Responder training
  4. Tabletop exercise
  5. Incident response plan

Correct answer: D

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

Option review:

A: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.

Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.

Question 32

A ticket at Litware Manufacturing asks an incident responder to improve responder readiness before a real incident occurs. Which choice addresses the requirement most directly? The team wants the most defensible analyst action before expanding the investigation.

  1. Responder training
  2. Forensic analysis
  3. Incident response plan
  4. Playbooks
  5. Incident-response tools

Correct answer: A

Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

Option review:

A: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.

B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.

Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.

Question 33

At Fourth Coffee, the response plan has three distinct requirements: coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; and standardize response steps for a common incident such as phishing or ransomware. Which THREE options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Lessons learned
  2. Business continuity and disaster recovery alignment
  3. Incident response plan
  4. Playbooks
  5. Responder training

Correct answers: A, B, D

Why: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements. Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services. Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

Option review:

A: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

B: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.

C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; standardize response steps for a common incident such as phishing or ransomware.

D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; standardize response steps for a common incident such as phishing or ransomware.

Learning point: Use Business continuity and disaster recovery alignment, Lessons learned, Playbooks when the key requirement is to coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; standardize response steps for a common incident such as phishing or ransomware.

Question 34

A review at Consolidated Messenger finds a gap: the team cannot reliably conduct deeper technical examination after containment to understand the intrusion. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.

  1. Business continuity and disaster recovery alignment
  2. Forensic analysis
  3. Root cause analysis
  4. Incident-response tools
  5. Tabletop exercise

Correct answer: B

Why: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.

C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

D: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.

Learning point: Use Forensic analysis when the key requirement is to conduct deeper technical examination after containment to understand the intrusion.

Question 35

a blue-team analyst at Adventure Works is comparing several approaches. The deciding requirement is to determine why the incident became possible rather than only what happened. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.

  1. Tabletop exercise
  2. Root cause analysis
  3. Business continuity and disaster recovery alignment
  4. Forensic analysis
  5. Lessons learned

Correct answer: B

Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

Option review:

A: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.

Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.

Question 36

While supporting a global corporate network, an incident coordinator is asked to turn incident experience into prioritized process and control improvements. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Business continuity and disaster recovery alignment
  2. Tabletop exercise
  3. Lessons learned
  4. Responder training
  5. Playbooks

Correct answer: C

Why: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

C: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

E: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.

Learning point: Use Lessons learned when the key requirement is to turn incident experience into prioritized process and control improvements.

Question 37

A new security procedure at Datum Fabrication must enable analysts to establish who does what and who can make decisions during an incident. Which option is the BEST choice? Base the decision on the primary security requirement, not on implementation convenience.

  1. Incident response plan
  2. Business continuity and disaster recovery alignment
  3. Incident-response tools
  4. Responder training
  5. Playbooks

Correct answer: A

Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

Option review:

A: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.

B: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

E: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.

Learning point: Use Incident response plan when the key requirement is to establish who does what and who can make decisions during an incident.

Question 38

The primary objective for Tailspin Toys is to ensure responders have tested investigation and containment tooling before an incident. Which selection best satisfies that objective in an e-commerce platform? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Business continuity and disaster recovery alignment
  2. Forensic analysis
  3. Incident-response tools
  4. Tabletop exercise
  5. Root cause analysis

Correct answer: C

Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

Option review:

A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.

D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.

Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.

Question 39

At Proseware Research, a malware analyst needs to standardize response steps for a common incident such as phishing or ransomware. Which option is the BEST fit for a restricted research segment? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Root cause analysis
  2. Incident-response tools
  3. Playbooks
  4. Tabletop exercise
  5. Lessons learned

Correct answer: C

Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

Option review:

A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.

D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.

Learning point: Use Playbooks when the key requirement is to standardize response steps for a common incident such as phishing or ransomware.

Question 40

During a security review, a SOC analyst must address two separate needs: test the response plan through a discussion-based simulated incident, and determine why the incident became possible rather than only what happened. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Forensic analysis
  2. Incident-response tools
  3. Tabletop exercise
  4. Responder training
  5. Root cause analysis

Correct answers: C, E

Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident. Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

Option review:

A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.

B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.

C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.

D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.

E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.

Learning point: Use Tabletop exercise, Root cause analysis when the key requirement is to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.

Popular posts

img