Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 856 discussion

Actual exam question from Isaca's CISM
Question #: 856
Topic #: 1
[All CISM Questions]

Which type of plan is PRIMARILY intended to reduce the potential impact of security events that may occur?

  • A. Incident response plan
  • B. Business continuity plan (BCP)
  • C. Security awareness plan
  • D. Disaster recovery plan (DRP)
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Booict
3 months, 3 weeks ago
My answer is A. The BCP addresses overall business operations and continuity, not just the immediate response to security incidents. manual business operation process can be kicked off while waiting for the system up and running. The IRP, on the other hand, is tailored to handle security events specifically, making it the most effective in reducing their potential impact.
upvoted 1 times
...
Marcelus1714
9 months, 1 week ago
Selected Answer: B
Maybe the word is PRIMARILY. The Incident response plan has other goals containment... erradication... etc. the primarily goal of a BCP is that
upvoted 2 times
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: A
Well, if the objective of containment is to reduce the impact of the incident, and we know that "containment" is one of the steps of incident response, then I'd say the correct answer here is A.
upvoted 1 times
AlexJacobson
9 months, 3 weeks ago
Also, notice that the question said "security events" and events can become incidents, and incidents can become disasters.
upvoted 2 times
...
...
AaronS1990
1 year, 2 months ago
Selected Answer: A
A- As per previous questions that cover the fact that incident response teams (and so incidents themselves) are there to mitigate impact
upvoted 2 times
...
Rowlandmarc
1 year, 3 months ago
Selected Answer: A
A. Potential impact reduction
upvoted 2 times
...
koala_lay
1 year, 3 months ago
Selected Answer: B
The correct answer is B. Business continuity plan (BCP). A BCP is designed to help minimize the impact of a security event, such as a natural disaster, cyber attack, or other unforeseen event, and ensure the continuity of your business operations.
upvoted 2 times
...
Goseu
1 year, 4 months ago
Selected Answer: A
A. Potential impact reduction
upvoted 2 times
...
CISSPST
1 year, 4 months ago
Security awareness is most relevant to reducing the likelihood of an incident, especially those related to social engineering and policy non-compliance. IRP's main focus is to reduce the impact/damage of the incident through containment. When the incident reaches a pre-defined threshold (RTO, RPO, SDO...), it is escalated to BCP which then focusses on the continuity of operations at acceptable level using minimum resources. It is an ongoing activity, or as mentioned in ISACA REVIEW MANUAL, ' a continuous process. DRP primarily focusses on recovering operations rather than reducing impacts.
upvoted 1 times
...
richck102
1 year, 4 months ago
Selected Answer: C
C. Security awareness plan
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...