CompTIA CySA+ CS0-003 Preparation And Post-Incident Activities Practice Test
Objective 3.3 • 40 original questions
This CompTIA CySA+ CS0-003 practice test focuses on objective 3.3: preparation and post-incident activities. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.
Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.
At Woodgrove Bank, a threat hunter has two simultaneous requirements: establish who does what and who can make decisions during an incident, and improve responder readiness before a real incident occurs. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: B, D
Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs. An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
Option review:
A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
B: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
Learning point: Use Incident response plan, Responder training when the key requirement is to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
A ticket at Humongous Insurance asks a risk analyst to ensure responders have tested investigation and containment tooling before an incident. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: C
Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.
Contoso Health is designing a combined control. It must standardize response steps for a common incident such as phishing or ransomware, and conduct deeper technical examination after containment to understand the intrusion. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.
Correct answers: A, D
Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware. Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Option review:
A: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
Learning point: Use Playbooks, Forensic analysis when the key requirement is to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
A review at Blue Yonder Airlines finds a gap: the team cannot reliably test the response plan through a discussion-based simulated incident. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: C
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
Option review:
A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
D: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.
a detection engineer at Lucerne Publishing is comparing several approaches. The deciding requirement is to improve responder readiness before a real incident occurs. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: E
Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
C: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
D: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
E: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.
While supporting an online banking environment, a vulnerability analyst is asked to coordinate cyber response with continuity and recovery of critical services. Which concept or tool is the clearest match? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: A
Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
B: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
D: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
Learning point: Use Business continuity and disaster recovery alignment when the key requirement is to coordinate cyber response with continuity and recovery of critical services.
A new security procedure at City Power Utilities must enable analysts to conduct deeper technical examination after containment to understand the intrusion. Which option is the BEST choice? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: A
Why: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Option review:
A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
Learning point: Use Forensic analysis when the key requirement is to conduct deeper technical examination after containment to understand the intrusion.
The primary objective for A. Datum Logistics is to determine why the incident became possible rather than only what happened. Which selection best satisfies that objective in a newly acquired subsidiary? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: A
Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
Option review:
A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.
At Northwind Traders, a security engineer has two simultaneous requirements: turn incident experience into prioritized process and control improvements, and test the response plan through a discussion-based simulated incident. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: A, B
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident. A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
Option review:
A: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
Learning point: Use Lessons learned, Tabletop exercise when the key requirement is to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
During an investigation at Alpine Ski House, the immediate requirement is to establish who does what and who can make decisions during an incident. What should a cloud security analyst select? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: D
Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
Option review:
A: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
Learning point: Use Incident response plan when the key requirement is to establish who does what and who can make decisions during an incident.
Coho Winery is updating its security operations standard for a branch-office network. Which option most directly helps the team ensure responders have tested investigation and containment tooling before an incident? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: B
Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
Option review:
A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.
A ticket at Litware Manufacturing asks an incident responder to standardize response steps for a common incident such as phishing or ransomware. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: D
Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
Option review:
A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
B: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
Learning point: Use Playbooks when the key requirement is to standardize response steps for a common incident such as phishing or ransomware.
In a multi-site enterprise, a security administrator must test the response plan through a discussion-based simulated incident. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: D
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
Option review:
A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
B: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.
A review at Consolidated Messenger finds a gap: the team cannot reliably improve responder readiness before a real incident occurs. Which option best closes that gap? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: A
Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Option review:
A: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
D: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.
Adventure Works is designing a combined control. It must coordinate cyber response with continuity and recovery of critical services, and establish who does what and who can make decisions during an incident. Which TWO options are most appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answers: A, B
Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services. An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
B: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.
E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.
Learning point: Use Business continuity and disaster recovery alignment, Incident response plan when the key requirement is to coordinate cyber response with continuity and recovery of critical services; establish who does what and who can make decisions during an incident.
During a security review, an incident coordinator must address two separate needs: conduct deeper technical examination after containment to understand the intrusion, and ensure responders have tested investigation and containment tooling before an incident. Select TWO. The team wants the most defensible analyst action before expanding the investigation.
Correct answers: B, E
Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident. Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Option review:
A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.
B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.
D: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Learning point: Use Forensic analysis, Incident-response tools when the key requirement is to conduct deeper technical examination after containment to understand the intrusion; ensure responders have tested investigation and containment tooling before an incident.
A new security procedure at Datum Fabrication must enable analysts to determine why the incident became possible rather than only what happened. Which option is the BEST choice? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: A
Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
Option review:
A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
B: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.
The primary objective for Tailspin Toys is to turn incident experience into prioritized process and control improvements. Which selection best satisfies that objective in an e-commerce platform? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: B
Why: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
Option review:
A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
C: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
Learning point: Use Lessons learned when the key requirement is to turn incident experience into prioritized process and control improvements.
At Proseware Research, a malware analyst needs to establish who does what and who can make decisions during an incident. Which option is the BEST fit for a restricted research segment? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: E
Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
Option review:
A: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
Learning point: Use Incident response plan when the key requirement is to establish who does what and who can make decisions during an incident.
During a security review, a SOC analyst must address two separate needs: ensure responders have tested investigation and containment tooling before an incident, and coordinate cyber response with continuity and recovery of critical services. Select TWO. The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answers: B, C
Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services. Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
Option review:
A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.
B: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
D: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.
E: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.
Learning point: Use Incident-response tools, Business continuity and disaster recovery alignment when the key requirement is to ensure responders have tested investigation and containment tooling before an incident; coordinate cyber response with continuity and recovery of critical services.
Woodgrove Bank is updating its security operations standard for a high-value payment environment. Which option most directly helps the team standardize response steps for a common incident such as phishing or ransomware? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: B
Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
Learning point: Use Playbooks when the key requirement is to standardize response steps for a common incident such as phishing or ransomware.
A ticket at Humongous Insurance asks a risk analyst to test the response plan through a discussion-based simulated incident. Which choice addresses the requirement most directly? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: C
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.
In a hospital network, a SOC analyst must improve responder readiness before a real incident occurs. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: E
Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Option review:
A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
D: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
E: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.
A review at Blue Yonder Airlines finds a gap: the team cannot reliably coordinate cyber response with continuity and recovery of critical services. Which option best closes that gap? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: A
Why: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
B: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
D: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services.
Learning point: Use Business continuity and disaster recovery alignment when the key requirement is to coordinate cyber response with continuity and recovery of critical services.
a detection engineer at Lucerne Publishing is comparing several approaches. The deciding requirement is to conduct deeper technical examination after containment to understand the intrusion. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: C
Why: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Option review:
A: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
C: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
Learning point: Use Forensic analysis when the key requirement is to conduct deeper technical examination after containment to understand the intrusion.
While supporting an online banking environment, a vulnerability analyst is asked to determine why the incident became possible rather than only what happened. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: B
Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
Option review:
A: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
E: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.
City Power Utilities is designing a combined control. It must turn incident experience into prioritized process and control improvements, and test the response plan through a discussion-based simulated incident. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.
Correct answers: B, D
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident. A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
Option review:
A: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
C: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
D: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
Learning point: Use Lessons learned, Tabletop exercise when the key requirement is to turn incident experience into prioritized process and control improvements; test the response plan through a discussion-based simulated incident.
During a security review, a security consultant must address two separate needs: establish who does what and who can make decisions during an incident, and improve responder readiness before a real incident occurs. Select TWO. The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answers: C, D
Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident. Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
Learning point: Use Incident response plan, Responder training when the key requirement is to establish who does what and who can make decisions during an incident; improve responder readiness before a real incident occurs.
At Northwind Traders, a security engineer needs to ensure responders have tested investigation and containment tooling before an incident. Which option is the BEST fit for a regional distribution network? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: E
Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
Option review:
A: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
B: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
D: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.
For a SaaS-heavy business, the team must accomplish both of these goals: standardize response steps for a common incident such as phishing or ransomware, and conduct deeper technical examination after containment to understand the intrusion. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: C, E
Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware. Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Option review:
A: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
E: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Learning point: Use Playbooks, Forensic analysis when the key requirement is to standardize response steps for a common incident such as phishing or ransomware; conduct deeper technical examination after containment to understand the intrusion.
Coho Winery is updating its security operations standard for a branch-office network. Which option most directly helps the team test the response plan through a discussion-based simulated incident? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: D
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
Option review:
A: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
C: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
E: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident.
Learning point: Use Tabletop exercise when the key requirement is to test the response plan through a discussion-based simulated incident.
A ticket at Litware Manufacturing asks an incident responder to improve responder readiness before a real incident occurs. Which choice addresses the requirement most directly? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: A
Why: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
Option review:
A: Training builds technical, procedural, and communication skills before responders must use them under pressure. It directly fits this scenario because the requirement is to improve responder readiness before a real incident occurs.
B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
E: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to improve responder readiness before a real incident occurs.
Learning point: Use Responder training when the key requirement is to improve responder readiness before a real incident occurs.
At Fourth Coffee, the response plan has three distinct requirements: coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; and standardize response steps for a common incident such as phishing or ransomware. Which THREE options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: A, B, D
Why: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements. Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services. Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
Option review:
A: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
B: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. It directly fits this scenario because the requirement is to coordinate cyber response with continuity and recovery of critical services.
C: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; standardize response steps for a common incident such as phishing or ransomware.
D: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
E: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; standardize response steps for a common incident such as phishing or ransomware.
Learning point: Use Business continuity and disaster recovery alignment, Lessons learned, Playbooks when the key requirement is to coordinate cyber response with continuity and recovery of critical services; turn incident experience into prioritized process and control improvements; standardize response steps for a common incident such as phishing or ransomware.
A review at Consolidated Messenger finds a gap: the team cannot reliably conduct deeper technical examination after containment to understand the intrusion. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: B
Why: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. It directly fits this scenario because the requirement is to conduct deeper technical examination after containment to understand the intrusion.
C: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
D: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
E: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to conduct deeper technical examination after containment to understand the intrusion.
Learning point: Use Forensic analysis when the key requirement is to conduct deeper technical examination after containment to understand the intrusion.
a blue-team analyst at Adventure Works is comparing several approaches. The deciding requirement is to determine why the incident became possible rather than only what happened. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: B
Why: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
Option review:
A: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
B: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
C: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
D: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine why the incident became possible rather than only what happened.
Learning point: Use Root cause analysis when the key requirement is to determine why the incident became possible rather than only what happened.
While supporting a global corporate network, an incident coordinator is asked to turn incident experience into prioritized process and control improvements. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: C
Why: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
B: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
C: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. It directly fits this scenario because the requirement is to turn incident experience into prioritized process and control improvements.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
E: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn incident experience into prioritized process and control improvements.
Learning point: Use Lessons learned when the key requirement is to turn incident experience into prioritized process and control improvements.
A new security procedure at Datum Fabrication must enable analysts to establish who does what and who can make decisions during an incident. Which option is the BEST choice? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: A
Why: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
Option review:
A: An incident response plan defines roles, authority, escalation, communications, priorities, and the overall process before an incident occurs. It directly fits this scenario because the requirement is to establish who does what and who can make decisions during an incident.
B: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
E: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to establish who does what and who can make decisions during an incident.
Learning point: Use Incident response plan when the key requirement is to establish who does what and who can make decisions during an incident.
The primary objective for Tailspin Toys is to ensure responders have tested investigation and containment tooling before an incident. Which selection best satisfies that objective in an e-commerce platform? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: C
Why: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
Option review:
A: Incident response must coordinate with BC/DR when an event threatens critical business services or requires alternate processing and restoration. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
B: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
C: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. It directly fits this scenario because the requirement is to ensure responders have tested investigation and containment tooling before an incident.
D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to ensure responders have tested investigation and containment tooling before an incident.
Learning point: Use Incident-response tools when the key requirement is to ensure responders have tested investigation and containment tooling before an incident.
At Proseware Research, a malware analyst needs to standardize response steps for a common incident such as phishing or ransomware. Which option is the BEST fit for a restricted research segment? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: C
Why: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
Option review:
A: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
C: Playbooks provide step-by-step guidance for recurring incident types while allowing analysts to adapt to circumstances. It directly fits this scenario because the requirement is to standardize response steps for a common incident such as phishing or ransomware.
D: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
E: A lessons-learned review captures what worked, what failed, and concrete improvements for controls, plans, tooling, and training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to standardize response steps for a common incident such as phishing or ransomware.
Learning point: Use Playbooks when the key requirement is to standardize response steps for a common incident such as phishing or ransomware.
During a security review, a SOC analyst must address two separate needs: test the response plan through a discussion-based simulated incident, and determine why the incident became possible rather than only what happened. Select TWO. The team wants the most defensible analyst action before expanding the investigation.
Correct answers: C, E
Why: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident. Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
Option review:
A: Post-incident forensics examines evidence in depth to establish activity, attribution clues, techniques, scope, and supporting facts. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.
B: Prepared tools include secure communications, evidence utilities, analysis platforms, clean media, scripts, and access needed during response. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.
C: A tabletop exercise walks stakeholders through a simulated scenario to test decisions, roles, communications, and gaps without affecting production. It directly fits this scenario because the requirement is to test the response plan through a discussion-based simulated incident.
D: Training builds technical, procedural, and communication skills before responders must use them under pressure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.
E: Root cause analysis identifies the underlying technical and process conditions that allowed the incident to occur or spread. It directly fits this scenario because the requirement is to determine why the incident became possible rather than only what happened.
Learning point: Use Tabletop exercise, Root cause analysis when the key requirement is to test the response plan through a discussion-based simulated incident; determine why the incident became possible rather than only what happened.
Popular posts
Recent Posts
