Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 719 discussion

Actual exam question from Isaca's CISM
Question #: 719
Topic #: 1
[All CISM Questions]

An incident management team is alerted to a suspected security event. Before classifying the suspected event as a security incident it is MOST important for the security manager to:

  • A. follow the incident response plan
  • B. follow the business continuity plan (BCP)
  • C. conduct an incident forensic analysis
  • D. notify the business process owner
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CarlLimps
Highly Voted 1 year, 8 months ago
Selected Answer: A
I like A as well here. Why would you reach out to the process owner if you aren't 100% sure it's a security incident? Verifying that it is an incident would be part of the incident response plan. Also the incident could be minor OR nothing, so NOT D.
upvoted 6 times
xcjxcj
8 months, 1 week ago
It is going to classifying, means verification is done. Minor or nothing is BO decision, so D.
upvoted 1 times
...
...
ServerBrain
Most Recent 1 month ago
Selected Answer: A
Question is about incident classification, so follow the incident response if not sure what classification to assign the incident.
upvoted 1 times
...
Booict
2 months, 4 weeks ago
Selected Answer: A
A - IRP is crucial because it provides a structured approach to handle suspected security events. The IRP outlines the necessary steps for identifying, assessing, and responding to incidents. Option D is important too, but notifying the business process owner typically comes after the initial steps outlined in the IRP. The primary goal is to ensure that the incident is managed effectively from the outset, which is why following the IRP is prioritized. Notifying the business process owner is important, but it typically comes after the initial steps outlined in the IRP. The primary goal is to ensure that the incident is managed effectively.
upvoted 1 times
...
shootnot
6 months, 1 week ago
D- based on the question, it is not an incident yet, therefore validation is required, and notifying the business owner would result in the validation as well as how to classify it.
upvoted 2 times
...
yottabyte
8 months ago
Selected Answer: D
The question has given the answer: "Before classifying the suspected event as a security incident it is MOST important for the security manager to", if it is a confirmed incident that you can follow the IRP, but notifying the business owner is important and discussion with the business process owner can validate if it is suspected or confirmed.
upvoted 3 times
...
POWNED
9 months, 3 weeks ago
Selected Answer: D
The ISM is in no way a SME when it comes to specific processes. The process owner needs to be contacted in order for them to classify if it is an incident.
upvoted 2 times
...
Cyberbug2021
11 months, 4 weeks ago
Selected Answer: D
business process owner will have input which will help classify the incident - it may not be a security incident so security incident response should not be initiated until it is classified as such
upvoted 2 times
...
Soleandheel
11 months, 4 weeks ago
D. notify the business process owner .......You cannot A. Follow the Incident Response Plan when the event is not yet classified as an incident. The question clearly states that the event has not yet been classified as an incident. D. is the correct answer not A.
upvoted 2 times
...
CISSPST
1 year, 1 month ago
Selected Answer: D
You cannot activate an incident response plan before declaring an event as an incident.
upvoted 3 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: A
A. Follow the incident response plan: Incident response plans are specifically designed to guide organizations in responding to and managing security incidents. They outline the steps to take when an incident occurs, including how to assess the situation, contain the incident, mitigate its impact, and recover from it. By following the incident response plan, the security manager can ensure that the appropriate actions are taken promptly to address the suspected security event.
upvoted 1 times
...
AaronS1990
1 year, 2 months ago
Selected Answer: D
I agree that at this stage it is still not an incident. The closest answer to "verifying the incident" IE further digging is D
upvoted 2 times
...
AidanSun
1 year, 3 months ago
Selected Answer: D
Dear all, please pay attention on the sentence "Before classifying the suspected event as a security incident", IRP should not be the correct answer, you should better to "Answer D".
upvoted 3 times
...
Goseu
1 year, 3 months ago
Selected Answer: D
Guys ,Given answer is correct , its still an event . IRP is initiated when its classified as an incident . Although D as an answer is not good .
upvoted 3 times
Marcelus1714
9 months, 2 weeks ago
and what do you do? to ask to the Process Owner if this is an incident? what if he does not know?
upvoted 1 times
...
...
richck102
1 year, 4 months ago
A. follow the incident response plan
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: A
A. follow the incident response plan. Following the incident response plan is crucial in situations where a suspected security event is detected. The incident response plan provides guidelines and procedures for handling security incidents, including the steps to be taken when a suspected event is identified. By following the incident response plan, the security manager ensures that the appropriate actions are taken promptly and effectively, minimizing the potential impact of the incident.
upvoted 3 times
...
Dravidian
1 year, 6 months ago
Selected Answer: A
Think it's A here. Notifying BO would also be a part of the incident response plan I would think.
upvoted 4 times
...
bambs
1 year, 8 months ago
Selected Answer: A
Before classifying the suspected event as a security incident, it is most important for the security manager to follow the incident response plan.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...