exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 148 discussion

Actual exam question from CompTIA's SY0-601
Question #: 148
Topic #: 1
[All SY0-601 Questions]

A company needs to validate its updated incident response plan using a real-world scenario that will test decision points and relevant incident response actions without interrupting daily operations. Which of the following would BEST meet the company's requirements?

  • A. Red-team exercise
  • B. Capture-the-flag exercise
  • C. Tabletop exercise
  • D. Phishing exercise
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TR3Y
Highly Voted 2 years, 7 months ago
A Cyber Security tabletop exercise is a discussion-based event (not real). If they are looking for "real world" solution to validate their IRP then the best option would be a "Red Team" as they can simulate a real-world event testing your organizations IRP. let me know If I am missing something.
upvoted 11 times
03allen
2 years, 6 months ago
"without interrupting daily operation" would be the reason.
upvoted 16 times
...
...
LordJaraxxus
Most Recent 1 year, 1 month ago
Selected Answer: C
A tabletop exercise (also called a desktop exercise) is discussionbased. A coordinator gathers participants in a classroom or conference room and leads them through one or more hypothetical scenarios such as a cyberattack or a natural disaster. As the coordinator introduces each stage of the scenario, the participants identify how they would respond based on an organization’s plan. This generates discussion about team members’ roles and responsibilities and the decision-making process during an incident. During a tabletop exercise, the coordinator may inject additional information. As an example, imagine the initial scenario is about a wildfire threatening a remote office. As participants discuss their responses, the coordinator may announce that the winds shifted and the wildfire is now threatening the organization’s main location. This additional scenario is planned in advance and mimics potential events that may occur in a real-life situation.
upvoted 2 times
...
tonnage800
1 year, 6 months ago
Selected Answer: C
Red team may not led to system failure but still have some affected to the daily operations through their actions, while tabletop (desktop exercise) is purely similate the incident in the meeting room, that complete has no affect to any systems
upvoted 3 times
...
Protract8593
1 year, 9 months ago
Selected Answer: C
A tabletop exercise is a type of scenario-based simulation that allows organizations to validate their incident response plan without executing the plan in a real-world environment. It involves a discussion-based approach, where key stakeholders come together in a controlled environment to walk through a hypothetical incident and discuss their responses, decision points, and actions. This exercise allows the organization to identify areas of improvement, test communication and coordination, and assess the effectiveness of their incident response procedures without disrupting regular operations.
upvoted 2 times
...
LiteralGod
1 year, 9 months ago
Selected Answer: A
Guys a Tabletop exercise would still interrupt daily operations, whereas a red team would usually be subbed to a third party.
upvoted 1 times
Remilia
1 year, 1 month ago
without interrupting daily operations means disrupting the tools. This is tabletop exercise, and this is being practiced by companies.
upvoted 1 times
...
Kurt43
1 year, 7 months ago
agreed. pulling resources from their desk to do tabletop interrupts their regular office functions.
upvoted 1 times
awscody
1 year, 7 months ago
You guys are literally thinking about this toooo deeply. "Regular office functions"?? A table top would involve the security team and stakeholders. That is their job. So no it would not interrupt regular function. Its another day in the office. Red Team will most likely be in the network and could take down critical services or actual servers which would / could interrupt daily ops.
upvoted 5 times
...
...
...
LeonardSnart
1 year, 11 months ago
Selected Answer: C
key point- test decision points and relevant incident response actions without interrupting daily operations "A tabletop exercise (also called a desktop exercise) is discussion-based. A coordinator gathers participants in a classroom or conference room and leads them through one or more hypothetical scenarios such as a cyberattack or a natural disaster. As the coordinator introduces each stage of the scenario, the participants identify how they would respond based on an organization’s plan. This generates discussion about team members’ roles and responsibilities and the decision-making process during an incident." -Security+ Get Certified Get Ahead SY0-601 by Darril Gibson
upvoted 4 times
...
fouserd
2 years ago
Selected Answer: C
A tabletop exercise would BEST meet the company’s requirements as it is designed to simulate an incident in a low-risk environment, such as a conference room, where participants discuss and walk through the response plan and identify gaps and opportunities for improvement1. This type of exercise tests decision points and relevant incident response actions without interrupting daily operations
upvoted 1 times
...
assfedassfinished
2 years ago
Selected Answer: C
It's table top. The other activities, even a phishing exercise, interrupts daily activities. For the phishing activity, you receive a non-work related email, that interrupts your daily activities.
upvoted 1 times
...
MasterControlProgram
2 years ago
Selected Answer: C
A tabletop exercise would BEST meet the company's requirements as it is designed to simulate an incident in a low-risk environment, such as a conference room, where participants discuss and walk through the response plan and identify gaps and opportunities for improvement. It would allow decision points to be tested, relevant incident response actions to be evaluated, and facilitate discussion of response and recovery procedures without interrupting daily operations. Red-team exercises, capture-the-flag exercises, and phishing exercises are all designed to simulate real-world attacks and test specific security controls, and may not be suitable for validating an incident response plan.
upvoted 1 times
...
gladtam
2 years, 1 month ago
The tabletop exercise is a verbally-simulated scenario that mimics a real cybersecurity incident which could have a damaging impact on your business continuity.
upvoted 2 times
...
mvckenzi
2 years, 1 month ago
Selected Answer: A
We're testing decision points and incident response actions. The answer is A. It's definitely not capture the flag. It's not TTXs. Those take away from daily ops. Phishing exercises isn't wrong, but red-table exercises would be the most correct fit since the network is being attacked and we're testing out our current incident response.
upvoted 2 times
...
MSCertifications
2 years, 3 months ago
Selected Answer: D
I'll go with phishing
upvoted 1 times
...
nicekoda
2 years, 4 months ago
Answer is Red team exercise. The actions are real world and intended to simulate the operational approach of a ransomware-style attack without overwriting sensitive files.
upvoted 1 times
...
alwaysrollin247
2 years, 4 months ago
Selected Answer: A
Red Team exercises differ from penetration testing in that they don’t focus on a single application or system, but instead set out to exploit multiple systems and potential avenues of attack. The gloves are off, and “Think like an attacker” is the rule of play. Usually, Red Teams are part of your internal security team, though sometimes they can be from external or dedicated agencies. While thinking like an attacker, a Red Team group acts as (and provides security feedback from the perspective of) a malicious threat or challenger. It’s up to the business’s dedicated security team – the Blue Team – to provide a suitable response in detecting, combating, and weakening their opposition. Prior to the Red Team exercise, it’s usual that the Blue Team won’t know the plan or what is coming. This is in order to make the exercise as realistic as possible. https://www.imperva.com/blog/what-are-red-team-exercises-and-why-are-they-important/
upvoted 1 times
...
KingTre
2 years, 4 months ago
Selected Answer: D
Although table top is a the most voted answer , "without interruping daily operations" leads me to think D would be correct. Tabletops involve physical participants to sit down and talk through incidents. This would take time and people away from daily operations. A phishing tactic could be done by 1 security officer and sent out as a daily email. Correct me if I'm wrong.
upvoted 3 times
assfedassfinished
2 years ago
Your phishing email would disrupt the daily activities of anyone who receives that email.
upvoted 1 times
...
ja1092m
1 year, 8 months ago
That's not what they mean by "daily operations" that's why you're getting confused. Daily operation is referring to technical work imo
upvoted 1 times
...
...
RonWonkers
2 years, 7 months ago
Selected Answer: C
C is correct
upvoted 3 times
...
serginljr
2 years, 7 months ago
Selected Answer: C
C is the correct answer
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago