Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 152 discussion

Actual exam question from Isaca's CISM
Question #: 152
Topic #: 1
[All CISM Questions]

Senior management is concerned that the incident response team took unapproved actions during incident response that put business objectives at risk. Which of the following is the BEST way for the information security manager to respond to this situation?

  • A. Update roles and responsibilities of the incident response team.
  • B. Train the incident response team on escalation procedures.
  • C. Implement a monitoring solution for incident response activities.
  • D. Validate that the information security strategy maps to corporate objectives.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mad68
Highly Voted 1 year, 6 months ago
Selected Answer: A
By updating the roles and responsibilities of the incident response team, the information security manager can clarify the expected actions and procedures that align with business objectives. This ensures that the team members understand their authorized actions and limitations during incident response, reducing the risk of unapproved actions that could impact business objectives.
upvoted 5 times
[Removed]
1 year, 4 months ago
this is a chatgpt answer.
upvoted 3 times
...
...
fac161f
Most Recent 2 months, 3 weeks ago
C Looking at it from both sides, Senior management could be wrong and does not fully understand IRT's roles and responsiblity. Updating Roles and Responsiblities address both sides. Key word for me is "Concerned" , that is not a direct statement of actions taken, just worried of what might have happened. This can be do to senior managements lack of knowledge in regard to the IRTs role and responsiblities. This of course Clarifies things for the IRT if it is needed. I see training as more a subset as it is kind of expected to be trained for your roles and responsiblity if you are lacking in that area.
upvoted 1 times
...
fac161f
2 months, 3 weeks ago
This is one of several questions where I dont agree with the "correct" answer. Will reference this in the ISACA study guide. I cant help but consider this theory vs reality. If that is the case I will have to follow the theory, but most of us know that Knowing your role does not always equate to knowing how to do your job. I selected B, Train the inceident responce team .....
upvoted 1 times
...
helg420
6 months, 2 weeks ago
Selected Answer: B
B. Train the incident response team on escalation procedures. If senior management is concerned that the incident response team took unapproved actions during an incident response, this indicates a possible lack of understanding or adherence to established escalation procedures. The best way to address this issue is to ensure that all members of the incident response team are adequately trained on escalation procedures. This training would emphasize when and how to escalate incidents within the organizational structure, ensuring that actions taken align with business objectives and that senior management is involved in decision-making when appropriate. This approach addresses the root cause of the concern by reinforcing the importance of following established protocols during an incident, thereby mitigating the risk of taking unapproved actions that could jeopardize business objectives. Updating roles and responsibilities (Option A) might help clarify expectations, but these actions do not directly address the issue of the team taking unapproved actions due to possibly inadequate knowledge or adherence to escalation procedures.
upvoted 1 times
...
afoo1314
8 months ago
Selected Answer: B
CISM Review Manual edition 16. pg. 263. "Management support- For example, the inability to respond to an incident due to existing silos within the enterprise, untrained team members due to underfunding, insufficient budget allocation to allow for effective and efficient response, ........" I guess IRT know what their roles but often untrained.
upvoted 1 times
...
Marcelus1714
9 months, 1 week ago
Selected Answer: A
If the team does not have clear their roles and responsabilities... then a training will be a bit useless, the trainings would be a failure. I guess is A.
upvoted 1 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: B
Option B
upvoted 1 times
...
POWNED
1 year ago
Selected Answer: B
Key word here in the question is unapproved. The incident team went outside the scope of their roles and responsibilities so training needs to be done. I would agree the answer would be A if the question did not involve "unapproved".
upvoted 4 times
...
oluchecpoint
1 year, 2 months ago
A. By reviewing and refining the roles and responsibilities, you can clarify the team's authorized actions, decision-making processes, and escalation procedures. This ensures that all team members understand their roles and the boundaries within which they should operate during an incident. It also helps prevent unauthorized actions that could potentially put business objectives at risk.
upvoted 1 times
...
pc2502
1 year, 3 months ago
Update roles and responsibilities of the incident response team. as issue likely lies with the team's understanding of their roles and responsibilities. By updating the roles and responsibilities of the incident response team, the information security manager can clarify what actions are approved and align their activities with the organization's overall business objectives.
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: A
update roles and responsibilities.
upvoted 1 times
...
richck102
1 year, 5 months ago
B. Train the incident response team on escalation procedures.
upvoted 1 times
...
Abhey
1 year, 6 months ago
Selected Answer: A
The BEST way for the information security manager to respond to the situation where senior management is concerned about unapproved actions taken by the incident response team is to update roles and responsibilities of the incident response team. This will ensure that the team has a clear understanding of their responsibilities and authority, as well as the expectations and limitations of their actions. By doing so, the incident response team will be better equipped to perform their duties within the defined guidelines, policies, and procedures, thereby reducing the risk of putting business objectives at risk.
upvoted 3 times
...
vavofa5697
1 year, 9 months ago
Selected Answer: B
Because of unapproved actions --> need training on escalation process.
upvoted 2 times
...
omaigret
1 year, 10 months ago
Selected Answer: B
not clear if roles and responsabilities will change effectively, training might me the answer (B)
upvoted 4 times
...
aokisan
1 year, 10 months ago
Selected Answer: B
unapproved action should be escalated properly.
upvoted 2 times
...
mohit05
1 year, 11 months ago
Selected Answer: C
C is the appropriate answer in my opinion
upvoted 1 times
dark_3k03r
1 year, 6 months ago
ChatGPT and Bard is the response to mohit05. Just in case you read these comments out of order. Cause for context, I use Google Search, Bard, ChatGPT, All-in-One, Essential CISM and my personal experience to answer questions. . . . but there really is no good answer for this question. That's why I suspect that mohit picked C , cause that is the only place I saw C as the answer.
upvoted 2 times
...
Ziggybooboo
1 year, 11 months ago
Not sure how a monitoring solution would help here, the incident response team did unapproved actions, A in my opinion
upvoted 3 times
...
dark_3k03r
1 year, 6 months ago
Was your opinion informed by Google Bard and ChatGPT... cause that is the answer I got from both. But it's not one I would have chosen.
upvoted 1 times
...
dark_3k03r
1 year, 6 months ago
For those curious I am not providing my regular breakdown A,B,C,D cause I don't like any of these answers. In my opinion the correct answer is for the SOC to perform a post-mortem and improve their SOPs. But that isn't an option and since I don't agree with any of the listed ones. I'm not voting.
upvoted 1 times
[Removed]
1 year, 4 months ago
I would choose C too, because A, B assume the concern of Senior Management is justified. You have to monitor to confirm what Management claims first
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...