An incident recovery plan is a statement of actions that should be taken before, during or after an incident. Identify which of the following is NOT an objective of the incident recovery plan?
A.
Creating new business processes to maintain profitability after incident
B.
Providing a standard for testing the recovery plan
C.
Avoiding the legal liabilities arising due to incident
The answer is C because legal has nothing to do with instant response; however, creating a new business plan is a lesson learned the last step of an incident response plan
I am going with C since "Creating new business processes to maintain profitability after incident" could be considered a post incident leason learned, making it an objective of the incident recovery plan.
A or C?
Objectives of incident recovery plan are
- provide security to computers
- optimize risks
- provide assurance to realibility
- provide standards for testing
- reduce decision making during an incident
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ITTechPass
4 months, 3 weeks agoColWilson
6 months, 2 weeks ago[Removed]
8 months agoMalferatus
1 year, 8 months agos3curity01
2 years, 4 months agolordosiris
2 years, 3 months agos3curity01
2 years, 3 months agos3curity01
2 years, 3 months agos3curity1
3 years, 3 months ago