Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 55 discussion

Actual exam question from Isaca's CISM
Question #: 55
Topic #: 1
[All CISM Questions]

Which of the following is MOST likely to be a component of a security incident escalation policy?

  • A. Names and telephone numbers of key management personnel
  • B. A severity-ranking mechanism tied only to the duration of the outage
  • C. Sample scripts and press releases for statements to media
  • D. Decision criteria for when to alert various groups
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alifjouj
2 months, 3 weeks ago
Selected Answer: D
the severity of an incident is NOT ONLY defined by its duration
upvoted 1 times
...
Manix
10 months ago
Selected Answer: D
page 288: The escalation process include prioritizing event information and decision process for determining when to alert various groups...
upvoted 2 times
...
Cyberbug2021
12 months ago
Selected Answer: D
definitely not B A security incident escalation policy defines the procedures for escalating security incidents based on their severity and potential impact. It outlines the specific criteria for determining when to involve various groups within the organization, such as senior management, legal counsel, and external experts. B. A severity-ranking mechanism tied only to the duration of the outage: Outage duration can be a factor in incident severity, but it's not the sole determinant. The policy should consider other factors such as the potential impact on data, systems, and reputation.
upvoted 2 times
...
Viperhunter
12 months ago
Selected Answer: D
A security incident escalation policy typically includes decision criteria that define when and how to escalate the incident to various levels of management or response teams. This includes clear guidelines on the severity, impact, or characteristics of the incident that warrant escalation to different groups within the organization. This helps ensure a timely and appropriate response to security incidents based on their nature and potential impact. While names and telephone numbers of key management personnel (option A) may be included in the policy, it is not the primary component. A severity-ranking mechanism tied only to the duration of the outage (option B) may not capture the full complexity of security incidents. Sample scripts and press releases for statements to the media (option C) are typically part of a communication plan rather than an escalation policy.
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
While the other options (A, B, and C) can also be important in the context of incident response, they are not as central to the core purpose of an escalation policy. For example: Names and telephone numbers of key management personnel (option A) can be part of an incident response plan but are not specific to escalation criteria. A severity-ranking mechanism tied only to the duration of the outage (option B) may not adequately capture the severity of all types of security incidents, and severity ranking should consider various factors beyond just duration. Sample scripts and press releases for statements to the media (option C) are important for managing communication during incidents but are typically part of communication plans rather than escalation policies.
upvoted 1 times
oluchecpoint
1 year, 2 months ago
D is the answer
upvoted 1 times
...
...
Patt70
1 year, 2 months ago
I work closely with SOC and I believe the answer is D. The question is about " the COMPONENT of a security incident escalation policy". Hence we need to have decision criteria or severity defined under the policy when/what/who/how to escalate. finally
upvoted 1 times
...
david124
1 year, 3 months ago
you guys clearly dont know what working in SOC is, Policy wont include names, this would include when and how. or else policy would change as ofter as promotions, terminations, etc policy FIRST needs to define what can be escalated, not who. taking IR plan for example they define what a incident is and when it can be escalated once it has reached a certain level
upvoted 1 times
...
rugerfan17
1 year, 5 months ago
Selected Answer: A
Before you can escalate, you need to know who to escalate to...
upvoted 1 times
CISSPST
1 year ago
Details of who (name) and where (number) to contact keep changing as people come and go whereas policy is a long-term document. Sorry, but A is not the answer.
upvoted 2 times
...
...
richck102
1 year, 6 months ago
D. Decision criteria for when to alert various groups
upvoted 2 times
...
mad68
1 year, 6 months ago
Selected Answer: D
A security incident escalation policy is a set of procedures that define how security incidents should be reported, investigated, and resolved. One of the key components of such a policy is decision criteria that outline when to escalate an incident to various groups, such as the incident response team, senior management, or law enforcement agencies.
upvoted 3 times
...
AomineDaiki
1 year, 7 months ago
A. I say A because before you know when to escalate, you need to have the information of those you need to escalate to. For that reason, my answer is A.
upvoted 1 times
...
dedfef
1 year, 8 months ago
Selected Answer: D
you need to know when to escalate
upvoted 3 times
...
STUDYER2
1 year, 9 months ago
Selected Answer: B
May be you need to know the severity level first then you can follow the alerting criteria
upvoted 2 times
dedfef
1 year, 7 months ago
wrong, that answer choice only speaks to the duration
upvoted 1 times
...
...
Antonivs
1 year, 10 months ago
Selected Answer: D
D & A for sure
upvoted 2 times
...
Prospect57
1 year, 10 months ago
Selected Answer: D
D. Decision Criteria to know *when* to escalate, which includes alerting relevant stakeholders/executives. Without it, you would not know when to escalate/alert.
upvoted 1 times
...
aokisan
1 year, 10 months ago
Selected Answer: B
severity ranking is important for escalation. alert is not escalation(D).
upvoted 1 times
...
Manzer
1 year, 11 months ago
Selected Answer: D
https://www.xmatters.com/blog/how-to-build-an-escalation-policy-for-effective-incident-management/
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...