CompTIA CySA+ CS0-003 Incident Response Reporting And Communication Practice Test

 

Objective 4.2 • 51 original questions

This CompTIA CySA+ CS0-003 practice test focuses on objective 4.2: incident response reporting and communication. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.

Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.

Question 1

A review at Tailspin Toys finds a gap: the team cannot reliably determine who must be informed before sending incident updates. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.

  1. Stakeholder identification
  2. Evidence summary
  3. Recommendations
  4. Incident declaration and escalation
  5. Public-relations communication

Correct answer: A

Why: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

Option review:

A: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

B: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

C: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

D: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

E: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

Learning point: Use Stakeholder identification when the key requirement is to determine who must be informed before sending incident updates.

Question 2

a malware analyst at Proseware Research is comparing several approaches. The deciding requirement is to move a serious security event into the formal incident process. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.

  1. Executive summary
  2. Incident declaration and escalation
  3. Law-enforcement coordination
  4. Mean time to remediate
  5. Mean time to respond

Correct answer: B

Why: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

Option review:

A: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

B: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

C: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

D: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

E: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

Learning point: Use Incident declaration and escalation when the key requirement is to move a serious security event into the formal incident process.

Question 3

While supporting a managed cloud environment, a SOC analyst is asked to brief senior leadership on the incident in business terms. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Executive summary
  2. Lessons-learned reporting
  3. Media communication
  4. Root cause reporting
  5. Stakeholder identification

Correct answer: A

Why: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. It directly fits this scenario because the requirement is to brief senior leadership on the incident in business terms.

Option review:

A: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. It directly fits this scenario because the requirement is to brief senior leadership on the incident in business terms.

B: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

C: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

D: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

E: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

Learning point: Use Executive summary when the key requirement is to brief senior leadership on the incident in business terms.

Question 4

A new security procedure at Woodgrove Bank must enable analysts to make the incident narrative complete enough for readers to understand the event. Which option is the BEST choice? Base the decision on the primary security requirement, not on implementation convenience.

  1. Public-relations communication
  2. Incident timeline
  3. Five-W incident narrative
  4. Evidence summary
  5. Stakeholder identification

Correct answer: C

Why: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. It directly fits this scenario because the requirement is to make the incident narrative complete enough for readers to understand the event.

Option review:

A: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

B: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

C: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. It directly fits this scenario because the requirement is to make the incident narrative complete enough for readers to understand the event.

D: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

E: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

Learning point: Use Five-W incident narrative when the key requirement is to make the incident narrative complete enough for readers to understand the event.

Question 5

The primary objective for Humongous Insurance is to turn the incident findings into specific future risk-reduction actions. Which selection best satisfies that objective in a regulated customer-data environment? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Legal communication
  2. Media communication
  3. Recommendations
  4. Regulatory reporting
  5. Customer communication

Correct answer: C

Why: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. It directly fits this scenario because the requirement is to turn the incident findings into specific future risk-reduction actions.

Option review:

A: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

B: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

C: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. It directly fits this scenario because the requirement is to turn the incident findings into specific future risk-reduction actions.

D: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

E: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

Learning point: Use Recommendations when the key requirement is to turn the incident findings into specific future risk-reduction actions.

Question 6

At Contoso Health, a SOC analyst needs to show the order and timing of important incident events. Which option is the BEST fit for a hospital network? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Incident timeline
  2. Public-relations communication
  3. Mean time to remediate
  4. Recommendations
  5. Evidence summary

Correct answer: A

Why: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. It directly fits this scenario because the requirement is to show the order and timing of important incident events.

Option review:

A: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. It directly fits this scenario because the requirement is to show the order and timing of important incident events.

B: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

C: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

D: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

E: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

Learning point: Use Incident timeline when the key requirement is to show the order and timing of important incident events.

Question 7

During a security review, a security operations engineer must address two separate needs: communicate the consequences of the incident rather than only technical indicators, and document what should change after the response is complete. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Impact statement
  2. Lessons-learned reporting
  3. Mean time to remediate
  4. Media communication
  5. Alert-volume metric

Correct answers: A, B

Why: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. It directly fits this scenario because the requirement is to communicate the consequences of the incident rather than only technical indicators. Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

Option review:

A: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. It directly fits this scenario because the requirement is to communicate the consequences of the incident rather than only technical indicators.

B: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

C: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

D: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

E: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

Learning point: Use Impact statement, Lessons-learned reporting when the key requirement is to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

Question 8

At Lucerne Publishing, a detection engineer has two simultaneous requirements: communicate what is and is not currently known to be affected, and measure how quickly the organization discovers incidents. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Scope statement
  2. Law-enforcement coordination
  3. Mean time to respond
  4. Mean time to detect
  5. Lessons-learned reporting

Correct answers: A, D

Why: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected. MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

Option review:

A: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected.

B: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected; measure how quickly the organization discovers incidents.

C: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected; measure how quickly the organization discovers incidents.

D: MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

E: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected; measure how quickly the organization discovers incidents.

Learning point: Use Scope statement, Mean time to detect when the key requirement is to communicate what is and is not currently known to be affected; measure how quickly the organization discovers incidents.

Question 9

For an online banking environment, the team must accomplish both of these goals: support incident conclusions with traceable investigative evidence, and measure speed from detection to meaningful response action. Which TWO choices together provide the best match? Assume the activity is authorized and must follow normal enterprise change control.

  1. Executive summary
  2. Law-enforcement coordination
  3. Mean time to respond
  4. Evidence summary
  5. Impact statement

Correct answers: C, D

Why: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. It directly fits this scenario because the requirement is to measure speed from detection to meaningful response action. The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. It directly fits this scenario because the requirement is to support incident conclusions with traceable investigative evidence.

Option review:

A: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence; measure speed from detection to meaningful response action.

B: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence; measure speed from detection to meaningful response action.

C: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. It directly fits this scenario because the requirement is to measure speed from detection to meaningful response action.

D: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. It directly fits this scenario because the requirement is to support incident conclusions with traceable investigative evidence.

E: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence; measure speed from detection to meaningful response action.

Learning point: Use Evidence summary, Mean time to respond when the key requirement is to support incident conclusions with traceable investigative evidence; measure speed from detection to meaningful response action.

Question 10

In a segmented industrial environment, an OT security analyst must coordinate incident information when legal obligations or litigation risk are involved. Which approach is MOST appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. Root cause reporting
  2. Five-W incident narrative
  3. Legal communication
  4. Public-relations communication
  5. Scope statement

Correct answer: C

Why: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. It directly fits this scenario because the requirement is to coordinate incident information when legal obligations or litigation risk are involved.

Option review:

A: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved.

B: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved.

C: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. It directly fits this scenario because the requirement is to coordinate incident information when legal obligations or litigation risk are involved.

D: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved.

E: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved.

Learning point: Use Legal communication when the key requirement is to coordinate incident information when legal obligations or litigation risk are involved.

Question 11

A review at A. Datum Logistics finds a gap: the team cannot reliably prepare public messaging about a visible incident. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Customer communication
  2. Public-relations communication
  3. Law-enforcement coordination
  4. Lessons-learned reporting
  5. Executive summary

Correct answer: B

Why: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. It directly fits this scenario because the requirement is to prepare public messaging about a visible incident.

Option review:

A: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

B: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. It directly fits this scenario because the requirement is to prepare public messaging about a visible incident.

C: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

D: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

E: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

Learning point: Use Public-relations communication when the key requirement is to prepare public messaging about a visible incident.

Question 12

a security engineer at Northwind Traders is comparing several approaches. The deciding requirement is to inform affected customers about impact and protective actions. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.

  1. Mean time to detect
  2. Customer communication
  3. Root cause reporting
  4. Mean time to respond
  5. Incident declaration and escalation

Correct answer: B

Why: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. It directly fits this scenario because the requirement is to inform affected customers about impact and protective actions.

Option review:

A: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions.

B: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. It directly fits this scenario because the requirement is to inform affected customers about impact and protective actions.

C: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions.

D: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions.

E: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions.

Learning point: Use Customer communication when the key requirement is to inform affected customers about impact and protective actions.

Question 13

For a SaaS-heavy business, the team must accomplish both of these goals: respond to press inquiries without exposing unverified technical details, and move a serious security event into the formal incident process. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Incident declaration and escalation
  2. Executive summary
  3. Media communication
  4. Scope statement
  5. Evidence summary

Correct answers: A, C

Why: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process. Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. It directly fits this scenario because the requirement is to respond to press inquiries without exposing unverified technical details.

Option review:

A: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

B: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details; move a serious security event into the formal incident process.

C: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. It directly fits this scenario because the requirement is to respond to press inquiries without exposing unverified technical details.

D: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details; move a serious security event into the formal incident process.

E: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details; move a serious security event into the formal incident process.

Learning point: Use Media communication, Incident declaration and escalation when the key requirement is to respond to press inquiries without exposing unverified technical details; move a serious security event into the formal incident process.

Question 14

A new security procedure at Coho Winery must enable analysts to meet a legally required incident-notification deadline. Which option is the BEST choice? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Stakeholder identification
  2. Evidence summary
  3. Incident declaration and escalation
  4. Regulatory reporting
  5. Scope statement

Correct answer: D

Why: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. It directly fits this scenario because the requirement is to meet a legally required incident-notification deadline.

Option review:

A: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

B: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

C: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

D: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. It directly fits this scenario because the requirement is to meet a legally required incident-notification deadline.

E: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

Learning point: Use Regulatory reporting when the key requirement is to meet a legally required incident-notification deadline.

Question 15

The primary objective for Litware Manufacturing is to coordinate a criminal cyber investigation with authorities. Which selection best satisfies that objective in a manufacturing plant? The team wants the most defensible analyst action before expanding the investigation.

  1. Law-enforcement coordination
  2. Alert-volume metric
  3. Mean time to detect
  4. Media communication
  5. Mean time to remediate

Correct answer: A

Why: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. It directly fits this scenario because the requirement is to coordinate a criminal cyber investigation with authorities.

Option review:

A: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. It directly fits this scenario because the requirement is to coordinate a criminal cyber investigation with authorities.

B: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

C: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

D: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

E: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

Learning point: Use Law-enforcement coordination when the key requirement is to coordinate a criminal cyber investigation with authorities.

Question 16

At Fourth Coffee, a security administrator needs to document the underlying condition that enabled the compromise. Which option is the BEST fit for a multi-site enterprise? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Lessons-learned reporting
  2. Alert-volume metric
  3. Root cause reporting
  4. Customer communication
  5. Recommendations

Correct answer: C

Why: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. It directly fits this scenario because the requirement is to document the underlying condition that enabled the compromise.

Option review:

A: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

B: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

C: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. It directly fits this scenario because the requirement is to document the underlying condition that enabled the compromise.

D: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

E: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

Learning point: Use Root cause reporting when the key requirement is to document the underlying condition that enabled the compromise.

Question 17

During an investigation at Consolidated Messenger, the immediate requirement is to document what should change after the response is complete. What should a response lead select? Assume the activity is authorized and must follow normal enterprise change control.

  1. Alert-volume metric
  2. Executive summary
  3. Legal communication
  4. Lessons-learned reporting
  5. Law-enforcement coordination

Correct answer: D

Why: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

Option review:

A: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

B: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

C: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

D: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

E: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

Learning point: Use Lessons-learned reporting when the key requirement is to document what should change after the response is complete.

Question 18

Adventure Works is updating its security operations standard for a hybrid-cloud workload. Which option most directly helps the team measure how quickly the organization discovers incidents? Assume no additional product-specific features are available beyond the concepts listed.

  1. Legal communication
  2. Regulatory reporting
  3. Scope statement
  4. Stakeholder identification
  5. Mean time to detect

Correct answer: E

Why: MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

Option review:

A: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

B: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

C: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

D: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

E: MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

Learning point: Use Mean time to detect when the key requirement is to measure how quickly the organization discovers incidents.

Question 19

A ticket at Wide World Importers asks an incident coordinator to measure speed from detection to meaningful response action. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Media communication
  2. Lessons-learned reporting
  3. Mean time to respond
  4. Public-relations communication
  5. Customer communication

Correct answer: C

Why: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. It directly fits this scenario because the requirement is to measure speed from detection to meaningful response action.

Option review:

A: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action.

B: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action.

C: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. It directly fits this scenario because the requirement is to measure speed from detection to meaningful response action.

D: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action.

E: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action.

Learning point: Use Mean time to respond when the key requirement is to measure speed from detection to meaningful response action.

Question 20

In a mixed Windows and Linux estate, a security architect must measure how quickly incidents are fully remediated. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.

  1. Executive summary
  2. Mean time to remediate
  3. Law-enforcement coordination
  4. Impact statement
  5. Recommendations

Correct answer: B

Why: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated.

Option review:

A: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

B: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated.

C: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

D: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

E: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

Learning point: Use Mean time to remediate when the key requirement is to measure how quickly incidents are fully remediated.

Question 21

A review at Tailspin Toys finds a gap: the team cannot reliably measure analyst workload pressure caused by the number of generated alerts. Which option best closes that gap? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Lessons-learned reporting
  2. Regulatory reporting
  3. Stakeholder identification
  4. Alert-volume metric
  5. Scope statement

Correct answer: D

Why: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. It directly fits this scenario because the requirement is to measure analyst workload pressure caused by the number of generated alerts.

Option review:

A: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts.

B: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts.

C: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts.

D: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. It directly fits this scenario because the requirement is to measure analyst workload pressure caused by the number of generated alerts.

E: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts.

Learning point: Use Alert-volume metric when the key requirement is to measure analyst workload pressure caused by the number of generated alerts.

Question 22

a malware analyst at Proseware Research is comparing several approaches. The deciding requirement is to determine who must be informed before sending incident updates. Which option should be chosen? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Five-W incident narrative
  2. Stakeholder identification
  3. Mean time to respond
  4. Incident timeline
  5. Mean time to remediate

Correct answer: B

Why: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

Option review:

A: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

B: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

C: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

D: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

E: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

Learning point: Use Stakeholder identification when the key requirement is to determine who must be informed before sending incident updates.

Question 23

During a security review, a SOC analyst must address two separate needs: move a serious security event into the formal incident process, and inform affected customers about impact and protective actions. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Media communication
  2. Incident declaration and escalation
  3. Executive summary
  4. Customer communication
  5. Alert-volume metric

Correct answers: B, D

Why: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process. Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. It directly fits this scenario because the requirement is to inform affected customers about impact and protective actions.

Option review:

A: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process; inform affected customers about impact and protective actions.

B: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

C: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process; inform affected customers about impact and protective actions.

D: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. It directly fits this scenario because the requirement is to inform affected customers about impact and protective actions.

E: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process; inform affected customers about impact and protective actions.

Learning point: Use Incident declaration and escalation, Customer communication when the key requirement is to move a serious security event into the formal incident process; inform affected customers about impact and protective actions.

Question 24

A new security procedure at Woodgrove Bank must enable analysts to brief senior leadership on the incident in business terms. Which option is the BEST choice? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Law-enforcement coordination
  2. Alert-volume metric
  3. Executive summary
  4. Incident declaration and escalation
  5. Scope statement

Correct answer: C

Why: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. It directly fits this scenario because the requirement is to brief senior leadership on the incident in business terms.

Option review:

A: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

B: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

C: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. It directly fits this scenario because the requirement is to brief senior leadership on the incident in business terms.

D: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

E: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

Learning point: Use Executive summary when the key requirement is to brief senior leadership on the incident in business terms.

Question 25

The primary objective for Humongous Insurance is to make the incident narrative complete enough for readers to understand the event. Which selection best satisfies that objective in a regulated customer-data environment? Assume the activity is authorized and must follow normal enterprise change control.

  1. Public-relations communication
  2. Mean time to respond
  3. Impact statement
  4. Five-W incident narrative
  5. Evidence summary

Correct answer: D

Why: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. It directly fits this scenario because the requirement is to make the incident narrative complete enough for readers to understand the event.

Option review:

A: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

B: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

C: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

D: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. It directly fits this scenario because the requirement is to make the incident narrative complete enough for readers to understand the event.

E: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event.

Learning point: Use Five-W incident narrative when the key requirement is to make the incident narrative complete enough for readers to understand the event.

Question 26

At Contoso Health, a SOC analyst needs to turn the incident findings into specific future risk-reduction actions. Which option is the BEST fit for a hospital network? Assume no additional product-specific features are available beyond the concepts listed.

  1. Scope statement
  2. Incident declaration and escalation
  3. Regulatory reporting
  4. Recommendations
  5. Mean time to respond

Correct answer: D

Why: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. It directly fits this scenario because the requirement is to turn the incident findings into specific future risk-reduction actions.

Option review:

A: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

B: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

C: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

D: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. It directly fits this scenario because the requirement is to turn the incident findings into specific future risk-reduction actions.

E: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

Learning point: Use Recommendations when the key requirement is to turn the incident findings into specific future risk-reduction actions.

Question 27

For an airline operations network, a security operations engineer must satisfy all three needs: show the order and timing of important incident events; respond to press inquiries without exposing unverified technical details; and measure how quickly incidents are fully remediated. Select THREE. The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Incident timeline
  2. Mean time to remediate
  3. Media communication
  4. Public-relations communication
  5. Executive summary

Correct answers: A, B, C

Why: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. It directly fits this scenario because the requirement is to show the order and timing of important incident events. Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated. Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. It directly fits this scenario because the requirement is to respond to press inquiries without exposing unverified technical details.

Option review:

A: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. It directly fits this scenario because the requirement is to show the order and timing of important incident events.

B: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated.

C: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. It directly fits this scenario because the requirement is to respond to press inquiries without exposing unverified technical details.

D: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events; respond to press inquiries without exposing unverified technical details; measure how quickly incidents are fully remediated.

E: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events; respond to press inquiries without exposing unverified technical details; measure how quickly incidents are fully remediated.

Learning point: Use Incident timeline, Media communication, Mean time to remediate when the key requirement is to show the order and timing of important incident events; respond to press inquiries without exposing unverified technical details; measure how quickly incidents are fully remediated.

Question 28

At Lucerne Publishing, a detection engineer has two simultaneous requirements: communicate the consequences of the incident rather than only technical indicators, and document what should change after the response is complete. Which TWO options should be selected? Base the decision on the primary security requirement, not on implementation convenience.

  1. Incident declaration and escalation
  2. Impact statement
  3. Lessons-learned reporting
  4. Mean time to detect
  5. Recommendations

Correct answers: B, C

Why: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. It directly fits this scenario because the requirement is to communicate the consequences of the incident rather than only technical indicators. Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

Option review:

A: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

B: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. It directly fits this scenario because the requirement is to communicate the consequences of the incident rather than only technical indicators.

C: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

D: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

E: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

Learning point: Use Impact statement, Lessons-learned reporting when the key requirement is to communicate the consequences of the incident rather than only technical indicators; document what should change after the response is complete.

Question 29

A ticket at Fabrikam Finance asks a vulnerability analyst to communicate what is and is not currently known to be affected. Which choice addresses the requirement most directly? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Mean time to remediate
  2. Legal communication
  3. Scope statement
  4. Stakeholder identification
  5. Mean time to detect

Correct answer: C

Why: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected.

Option review:

A: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

B: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

C: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected.

D: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

E: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

Learning point: Use Scope statement when the key requirement is to communicate what is and is not currently known to be affected.

Question 30

At City Power Utilities, the response plan has three distinct requirements: support incident conclusions with traceable investigative evidence; document the underlying condition that enabled the compromise; and move a serious security event into the formal incident process. Which THREE options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Incident declaration and escalation
  2. Mean time to respond
  3. Root cause reporting
  4. Evidence summary
  5. Scope statement

Correct answers: A, C, D

Why: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process. Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. It directly fits this scenario because the requirement is to document the underlying condition that enabled the compromise. The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. It directly fits this scenario because the requirement is to support incident conclusions with traceable investigative evidence.

Option review:

A: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

B: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence; document the underlying condition that enabled the compromise; move a serious security event into the formal incident process.

C: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. It directly fits this scenario because the requirement is to document the underlying condition that enabled the compromise.

D: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. It directly fits this scenario because the requirement is to support incident conclusions with traceable investigative evidence.

E: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence; document the underlying condition that enabled the compromise; move a serious security event into the formal incident process.

Learning point: Use Evidence summary, Root cause reporting, Incident declaration and escalation when the key requirement is to support incident conclusions with traceable investigative evidence; document the underlying condition that enabled the compromise; move a serious security event into the formal incident process.

Question 31

During a security review, a security consultant must address two separate needs: coordinate incident information when legal obligations or litigation risk are involved, and measure how quickly incidents are fully remediated. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Mean time to remediate
  2. Impact statement
  3. Legal communication
  4. Law-enforcement coordination
  5. Evidence summary

Correct answers: A, C

Why: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated. Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. It directly fits this scenario because the requirement is to coordinate incident information when legal obligations or litigation risk are involved.

Option review:

A: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated.

B: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved; measure how quickly incidents are fully remediated.

C: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. It directly fits this scenario because the requirement is to coordinate incident information when legal obligations or litigation risk are involved.

D: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved; measure how quickly incidents are fully remediated.

E: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate incident information when legal obligations or litigation risk are involved; measure how quickly incidents are fully remediated.

Learning point: Use Legal communication, Mean time to remediate when the key requirement is to coordinate incident information when legal obligations or litigation risk are involved; measure how quickly incidents are fully remediated.

Question 32

a security engineer at Northwind Traders is comparing several approaches. The deciding requirement is to prepare public messaging about a visible incident. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Public-relations communication
  2. Stakeholder identification
  3. Evidence summary
  4. Law-enforcement coordination
  5. Five-W incident narrative

Correct answer: A

Why: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. It directly fits this scenario because the requirement is to prepare public messaging about a visible incident.

Option review:

A: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. It directly fits this scenario because the requirement is to prepare public messaging about a visible incident.

B: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

C: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

D: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

E: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prepare public messaging about a visible incident.

Learning point: Use Public-relations communication when the key requirement is to prepare public messaging about a visible incident.

Question 33

For a SaaS-heavy business, the team must accomplish both of these goals: inform affected customers about impact and protective actions, and determine who must be informed before sending incident updates. Which TWO choices together provide the best match? Assume the activity is authorized and must follow normal enterprise change control.

  1. Customer communication
  2. Stakeholder identification
  3. Legal communication
  4. Evidence summary
  5. Impact statement

Correct answers: A, B

Why: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. It directly fits this scenario because the requirement is to inform affected customers about impact and protective actions. Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

Option review:

A: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. It directly fits this scenario because the requirement is to inform affected customers about impact and protective actions.

B: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

C: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions; determine who must be informed before sending incident updates.

D: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions; determine who must be informed before sending incident updates.

E: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to inform affected customers about impact and protective actions; determine who must be informed before sending incident updates.

Learning point: Use Customer communication, Stakeholder identification when the key requirement is to inform affected customers about impact and protective actions; determine who must be informed before sending incident updates.

Question 34

A new security procedure at Coho Winery must enable analysts to respond to press inquiries without exposing unverified technical details. Which option is the BEST choice? Assume no additional product-specific features are available beyond the concepts listed.

  1. Public-relations communication
  2. Media communication
  3. Impact statement
  4. Law-enforcement coordination
  5. Mean time to remediate

Correct answer: B

Why: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. It directly fits this scenario because the requirement is to respond to press inquiries without exposing unverified technical details.

Option review:

A: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details.

B: Media responses should use authorized spokespeople, confirmed facts, and coordinated messaging. It directly fits this scenario because the requirement is to respond to press inquiries without exposing unverified technical details.

C: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details.

D: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details.

E: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to respond to press inquiries without exposing unverified technical details.

Learning point: Use Media communication when the key requirement is to respond to press inquiries without exposing unverified technical details.

Question 35

The primary objective for Litware Manufacturing is to meet a legally required incident-notification deadline. Which selection best satisfies that objective in a manufacturing plant? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Stakeholder identification
  2. Public-relations communication
  3. Customer communication
  4. Regulatory reporting
  5. Recommendations

Correct answer: D

Why: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. It directly fits this scenario because the requirement is to meet a legally required incident-notification deadline.

Option review:

A: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

B: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

C: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

D: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. It directly fits this scenario because the requirement is to meet a legally required incident-notification deadline.

E: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to meet a legally required incident-notification deadline.

Learning point: Use Regulatory reporting when the key requirement is to meet a legally required incident-notification deadline.

Question 36

At Fourth Coffee, a security administrator needs to coordinate a criminal cyber investigation with authorities. Which option is the BEST fit for a multi-site enterprise? Base the decision on the primary security requirement, not on implementation convenience.

  1. Mean time to detect
  2. Root cause reporting
  3. Mean time to remediate
  4. Regulatory reporting
  5. Law-enforcement coordination

Correct answer: E

Why: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. It directly fits this scenario because the requirement is to coordinate a criminal cyber investigation with authorities.

Option review:

A: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

B: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

C: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

D: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to coordinate a criminal cyber investigation with authorities.

E: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. It directly fits this scenario because the requirement is to coordinate a criminal cyber investigation with authorities.

Learning point: Use Law-enforcement coordination when the key requirement is to coordinate a criminal cyber investigation with authorities.

Question 37

During an investigation at Consolidated Messenger, the immediate requirement is to document the underlying condition that enabled the compromise. What should a response lead select? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Executive summary
  2. Alert-volume metric
  3. Incident declaration and escalation
  4. Mean time to detect
  5. Root cause reporting

Correct answer: E

Why: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. It directly fits this scenario because the requirement is to document the underlying condition that enabled the compromise.

Option review:

A: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

B: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

C: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

D: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document the underlying condition that enabled the compromise.

E: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. It directly fits this scenario because the requirement is to document the underlying condition that enabled the compromise.

Learning point: Use Root cause reporting when the key requirement is to document the underlying condition that enabled the compromise.

Question 38

Adventure Works is updating its security operations standard for a hybrid-cloud workload. Which option most directly helps the team document what should change after the response is complete? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Executive summary
  2. Lessons-learned reporting
  3. Root cause reporting
  4. Recommendations
  5. Alert-volume metric

Correct answer: B

Why: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

Option review:

A: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

B: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. It directly fits this scenario because the requirement is to document what should change after the response is complete.

C: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

D: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

E: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to document what should change after the response is complete.

Learning point: Use Lessons-learned reporting when the key requirement is to document what should change after the response is complete.

Question 39

A ticket at Wide World Importers asks an incident coordinator to measure how quickly the organization discovers incidents. Which choice addresses the requirement most directly? The team wants the most defensible analyst action before expanding the investigation.

  1. Public-relations communication
  2. Mean time to detect
  3. Mean time to remediate
  4. Law-enforcement coordination
  5. Root cause reporting

Correct answer: B

Why: MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

Option review:

A: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

B: MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

C: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

D: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

E: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly the organization discovers incidents.

Learning point: Use Mean time to detect when the key requirement is to measure how quickly the organization discovers incidents.

Question 40

At Datum Fabrication, a security architect has two simultaneous requirements: measure speed from detection to meaningful response action, and communicate what is and is not currently known to be affected. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Scope statement
  2. Mean time to respond
  3. Incident declaration and escalation
  4. Root cause reporting
  5. Regulatory reporting

Correct answers: A, B

Why: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected. Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. It directly fits this scenario because the requirement is to measure speed from detection to meaningful response action.

Option review:

A: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected.

B: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. It directly fits this scenario because the requirement is to measure speed from detection to meaningful response action.

C: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action; communicate what is and is not currently known to be affected.

D: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action; communicate what is and is not currently known to be affected.

E: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure speed from detection to meaningful response action; communicate what is and is not currently known to be affected.

Learning point: Use Mean time to respond, Scope statement when the key requirement is to measure speed from detection to meaningful response action; communicate what is and is not currently known to be affected.

Question 41

A review at Tailspin Toys finds a gap: the team cannot reliably measure how quickly incidents are fully remediated. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.

  1. Mean time to respond
  2. Five-W incident narrative
  3. Mean time to detect
  4. Public-relations communication
  5. Mean time to remediate

Correct answer: E

Why: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated.

Option review:

A: Mean time to respond measures how quickly response action begins after detection or declaration according to the organization definition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

B: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

C: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

D: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure how quickly incidents are fully remediated.

E: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. It directly fits this scenario because the requirement is to measure how quickly incidents are fully remediated.

Learning point: Use Mean time to remediate when the key requirement is to measure how quickly incidents are fully remediated.

Question 42

Proseware Research is designing a combined control. It must measure analyst workload pressure caused by the number of generated alerts, and coordinate incident information when legal obligations or litigation risk are involved. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. Alert-volume metric
  2. Executive summary
  3. Five-W incident narrative
  4. Legal communication
  5. Lessons-learned reporting

Correct answers: A, D

Why: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. It directly fits this scenario because the requirement is to measure analyst workload pressure caused by the number of generated alerts. Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. It directly fits this scenario because the requirement is to coordinate incident information when legal obligations or litigation risk are involved.

Option review:

A: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. It directly fits this scenario because the requirement is to measure analyst workload pressure caused by the number of generated alerts.

B: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts; coordinate incident information when legal obligations or litigation risk are involved.

C: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts; coordinate incident information when legal obligations or litigation risk are involved.

D: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. It directly fits this scenario because the requirement is to coordinate incident information when legal obligations or litigation risk are involved.

E: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to measure analyst workload pressure caused by the number of generated alerts; coordinate incident information when legal obligations or litigation risk are involved.

Learning point: Use Alert-volume metric, Legal communication when the key requirement is to measure analyst workload pressure caused by the number of generated alerts; coordinate incident information when legal obligations or litigation risk are involved.

Question 43

While supporting a managed cloud environment, a SOC analyst is asked to determine who must be informed before sending incident updates. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Mean time to detect
  2. Stakeholder identification
  3. Public-relations communication
  4. Law-enforcement coordination
  5. Recommendations

Correct answer: B

Why: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

Option review:

A: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

B: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. It directly fits this scenario because the requirement is to determine who must be informed before sending incident updates.

C: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

D: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

E: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine who must be informed before sending incident updates.

Learning point: Use Stakeholder identification when the key requirement is to determine who must be informed before sending incident updates.

Question 44

A new security procedure at Woodgrove Bank must enable analysts to move a serious security event into the formal incident process. Which option is the BEST choice? Base the decision on the primary security requirement, not on implementation convenience.

  1. Customer communication
  2. Law-enforcement coordination
  3. Alert-volume metric
  4. Scope statement
  5. Incident declaration and escalation

Correct answer: E

Why: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

Option review:

A: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

B: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

C: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

D: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to move a serious security event into the formal incident process.

E: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. It directly fits this scenario because the requirement is to move a serious security event into the formal incident process.

Learning point: Use Incident declaration and escalation when the key requirement is to move a serious security event into the formal incident process.

Question 45

The primary objective for Humongous Insurance is to brief senior leadership on the incident in business terms. Which selection best satisfies that objective in a regulated customer-data environment? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Alert-volume metric
  2. Scope statement
  3. Stakeholder identification
  4. Public-relations communication
  5. Executive summary

Correct answer: E

Why: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. It directly fits this scenario because the requirement is to brief senior leadership on the incident in business terms.

Option review:

A: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

B: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

C: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

D: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to brief senior leadership on the incident in business terms.

E: An executive summary presents business impact, status, decisions, and key actions without overwhelming leaders with raw technical detail. It directly fits this scenario because the requirement is to brief senior leadership on the incident in business terms.

Learning point: Use Executive summary when the key requirement is to brief senior leadership on the incident in business terms.

Question 46

At Contoso Health, the response plan has three distinct requirements: make the incident narrative complete enough for readers to understand the event; prepare public messaging about a visible incident; and measure how quickly the organization discovers incidents. Which THREE options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Customer communication
  2. Five-W incident narrative
  3. Mean time to detect
  4. Alert-volume metric
  5. Public-relations communication

Correct answers: B, C, E

Why: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. It directly fits this scenario because the requirement is to make the incident narrative complete enough for readers to understand the event. MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents. Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. It directly fits this scenario because the requirement is to prepare public messaging about a visible incident.

Option review:

A: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event; prepare public messaging about a visible incident; measure how quickly the organization discovers incidents.

B: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. It directly fits this scenario because the requirement is to make the incident narrative complete enough for readers to understand the event.

C: MTTD measures the average time from incident occurrence or observable activity to detection. It directly fits this scenario because the requirement is to measure how quickly the organization discovers incidents.

D: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to make the incident narrative complete enough for readers to understand the event; prepare public messaging about a visible incident; measure how quickly the organization discovers incidents.

E: Public relations coordinates accurate, approved external messaging and reduces contradictory or speculative statements. It directly fits this scenario because the requirement is to prepare public messaging about a visible incident.

Learning point: Use Five-W incident narrative, Public-relations communication, Mean time to detect when the key requirement is to make the incident narrative complete enough for readers to understand the event; prepare public messaging about a visible incident; measure how quickly the organization discovers incidents.

Question 47

During an investigation at Blue Yonder Airlines, the immediate requirement is to turn the incident findings into specific future risk-reduction actions. What should a security operations engineer select? The team wants the most defensible analyst action before expanding the investigation.

  1. Mean time to detect
  2. Recommendations
  3. Customer communication
  4. Scope statement
  5. Law-enforcement coordination

Correct answer: B

Why: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. It directly fits this scenario because the requirement is to turn the incident findings into specific future risk-reduction actions.

Option review:

A: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

B: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. It directly fits this scenario because the requirement is to turn the incident findings into specific future risk-reduction actions.

C: Customer notices should be timely, accurate, actionable, and coordinated with legal and regulatory obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

D: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

E: Law enforcement may be engaged for criminal activity, evidence sharing, threat coordination, or broader public-safety reasons. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn the incident findings into specific future risk-reduction actions.

Learning point: Use Recommendations when the key requirement is to turn the incident findings into specific future risk-reduction actions.

Question 48

Lucerne Publishing is updating its security operations standard for a remote-work environment. Which option most directly helps the team show the order and timing of important incident events? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Evidence summary
  2. Scope statement
  3. Mean time to remediate
  4. Stakeholder identification
  5. Incident timeline

Correct answer: E

Why: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. It directly fits this scenario because the requirement is to show the order and timing of important incident events.

Option review:

A: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

B: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

C: Mean time to remediate measures how long it takes to complete remediation or restore an acceptable secure state. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

D: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to show the order and timing of important incident events.

E: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. It directly fits this scenario because the requirement is to show the order and timing of important incident events.

Learning point: Use Incident timeline when the key requirement is to show the order and timing of important incident events.

Question 49

A ticket at Fabrikam Finance asks a vulnerability analyst to communicate the consequences of the incident rather than only technical indicators. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.

  1. Root cause reporting
  2. Alert-volume metric
  3. Lessons-learned reporting
  4. Stakeholder identification
  5. Impact statement

Correct answer: E

Why: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. It directly fits this scenario because the requirement is to communicate the consequences of the incident rather than only technical indicators.

Option review:

A: Root cause analysis explains the underlying failure that allowed the incident, not merely the immediate symptom. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators.

B: Alert volume tracks the quantity of alerts and can reveal workload, tuning needs, spikes, and changes in detection behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators.

C: Lessons learned capture improvements to prevention, detection, response, communications, and recovery based on the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators.

D: Incident communications begin by identifying who needs information, who owns decisions, and who has legal, operational, or executive responsibilities. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate the consequences of the incident rather than only technical indicators.

E: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. It directly fits this scenario because the requirement is to communicate the consequences of the incident rather than only technical indicators.

Learning point: Use Impact statement when the key requirement is to communicate the consequences of the incident rather than only technical indicators.

Question 50

In a segmented industrial environment, an OT security analyst must communicate what is and is not currently known to be affected. Which approach is MOST appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. Incident declaration and escalation
  2. Mean time to detect
  3. Five-W incident narrative
  4. Scope statement
  5. Regulatory reporting

Correct answer: D

Why: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected.

Option review:

A: Formal declaration and escalation activate the appropriate response level, authorities, teams, and notification obligations. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

B: MTTD measures the average time from incident occurrence or observable activity to detection. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

C: A strong incident report explains who, what, when, where, and why to provide a clear factual narrative. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

D: The scope section identifies affected users, systems, data, locations, and business processes and states known uncertainties. It directly fits this scenario because the requirement is to communicate what is and is not currently known to be affected.

E: Some incidents trigger reporting deadlines or content requirements to regulators based on jurisdiction and industry. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to communicate what is and is not currently known to be affected.

Learning point: Use Scope statement when the key requirement is to communicate what is and is not currently known to be affected.

Question 51

A review at A. Datum Logistics finds a gap: the team cannot reliably support incident conclusions with traceable investigative evidence. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Recommendations
  2. Legal communication
  3. Impact statement
  4. Evidence summary
  5. Incident timeline

Correct answer: D

Why: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. It directly fits this scenario because the requirement is to support incident conclusions with traceable investigative evidence.

Option review:

A: Recommendations convert investigation findings into prioritized improvements to controls, process, architecture, or training. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence.

B: Legal counsel may guide privilege, notification duties, preservation, contracts, and regulatory exposure. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence.

C: The impact section explains consequences to operations, data, customers, finances, compliance, or reputation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence.

D: The evidence section documents the data supporting conclusions while respecting integrity, chain-of-custody, privacy, and legal constraints. It directly fits this scenario because the requirement is to support incident conclusions with traceable investigative evidence.

E: A timeline sequences detections, attacker actions, analyst actions, communications, and recovery milestones. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to support incident conclusions with traceable investigative evidence.

Learning point: Use Evidence summary when the key requirement is to support incident conclusions with traceable investigative evidence.

Popular posts

img