Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 902 discussion

Actual exam question from Isaca's CISM
Question #: 902
Topic #: 1
[All CISM Questions]

While responding to a high-profile security incident, an information security manager observed several deficiencies in the current incident response plan. When would be the BEST time to update the plan?

  • A. While responding to the incident
  • B. During post-incident review
  • C. During a tabletop exercise
  • D. After a risk reassessment
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Booict
3 months, 3 weeks ago
My answer is B. Not sure why the correct answer is C? Option C is primarily designed for training and testing, rather than immediate plan updates during a real high-profile security incident.
upvoted 1 times
...
enk
11 months, 2 weeks ago
Selected Answer: B
B seems to be the best answer although, "during" post-incident review has me hung up a bit. It should be right after a post-incident review. During the post-incident review is providing you valuable information that will feed into updating the incident response plan.
upvoted 1 times
...
richck102
1 year, 1 month ago
Selected Answer: B
B. During post-incident review
upvoted 2 times
...
CISSPST
1 year, 1 month ago
Selected Answer: C
During the post incident review, lessons learned and recommendations for improvements are analyzed and documented. Updating processes and plans is not done at this stage. It is during the Planning & Preparation phase, that the recommendations from PIR are evaluated and implemented. Tabletop exercises could be a perfect opportunity to test the recommendations and update accordingly.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: D
D. After a risk reassessment Updating the incident response plan after a risk reassessment allows you to incorporate the lessons learned from the high-profile security incident and ensure that the plan is better aligned with the current threat landscape and organizational priorities. This approach allows for a more informed and proactive response to future incidents, taking into account any deficiencies and vulnerabilities identified during the incident response process.
upvoted 1 times
AaronS1990
1 year, 2 months ago
Stop with the ChatGPT. No one wants to see it
upvoted 2 times
CISSPST
1 year, 1 month ago
ChatGPT says B, not D. oluch.. has as much a right as any of us to post his responses, both right and wrong. So long as his comments not personal and are sticking to the guidelines......I'll just say thank you, oluch and good luck with your CISM. And no, I am not looking for a fight....just wanted to support all participants who are here to learn.
upvoted 3 times
...
...
...
AaronS1990
1 year, 2 months ago
Selected Answer: B
B as it says that there is currently an ongoing incident within which they have noticed issues. It is best to address them as soon as possible and that is during the post-incident review.
upvoted 2 times
...
Ewunia
1 year, 3 months ago
Selected Answer: B
agree B
upvoted 2 times
...
enojado
1 year, 3 months ago
Selected Answer: B
During post-incident review. This is typically the best time to update the plan because the team can reflect on what went well and what did not, and make necessary changes based on lessons learned.
upvoted 1 times
...
AidanSun
1 year, 3 months ago
Selected Answer: B
Should be B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...