exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 143 discussion

Actual exam question from Isaca's CISM
Question #: 143
Topic #: 1
[All CISM Questions]

During a post-incident review, the sequence and correlation of actions must be analyzed PRIMARILY based on:

  • A. a consolidated event timeline.
  • B. logs from systems involved.
  • C. interviews with personnel.
  • D. documents created during the incident.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
helg420
5 months, 1 week ago
Selected Answer: A
A. a consolidated event timeline. A consolidated event timeline is primarily used during a post-incident review to analyze the sequence and correlation of actions. This timeline combines data from various sources to provide a comprehensive overview of the incident from start to finish. It helps to understand the chronological order of events, how the incident unfolded, and how responses were made at each stage. By laying out the sequence of events in a linear timeline, it's easier to identify any delays, overlaps, or gaps in the response, which are crucial for improving future incident response strategies. While logs from systems involved (option B), interviews with personnel (option C), and documents created during the incident (option D) are valuable sources of information, they contribute to the creation of the consolidated event timeline rather than serve as primary analytical tools by themselves. These elements feed into the timeline, providing details and context that help to form a complete picture of the incident and the effectiveness of the response.
upvoted 2 times
...
Learner76
11 months ago
A - Key words - "Sequence"
upvoted 1 times
...
secdoc
1 year, 1 month ago
B,C,D are all used to create A
upvoted 1 times
...
todush
1 year, 2 months ago
The response depends on what you are considering in a "consolidated" timeline. If it includes the documents created during the incidents, response A is OK. Otherwise response D is obvious as it may also include the timeline.
upvoted 1 times
...
Pavan_Hanuman
1 year, 2 months ago
Selected Answer: D
D. documents created during the incident.
upvoted 1 times
...
richck102
1 year, 4 months ago
D. documents created during the incident.
upvoted 1 times
...
Aboodi000
1 year, 7 months ago
WHY IS NOT B?
upvoted 1 times
dark_3k03r
1 year, 6 months ago
Because there may be logs from the cloud service provider platform such apps, function and compute as a Service. So it's just not the system logs. But a consolidate timeline will include everything from everywhere.
upvoted 1 times
...
...
Broesweelies
1 year, 9 months ago
Selected Answer: A
Event timeline for sure.
upvoted 3 times
...
Prospect57
1 year, 9 months ago
D was my guess. However, if the "event timeline" includes these documents and logs (Choice D & B), then I can understand A being the answer.
upvoted 1 times
...
aokisan
1 year, 9 months ago
Selected Answer: A
event timeline is most reliable.
upvoted 4 times
...
mohit05
1 year, 10 months ago
Selected Answer: D
D. documents created during the incident is more appropriate
upvoted 4 times
Ziggybooboo
1 year, 10 months ago
Agreed
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago