exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 237 discussion

Actual exam question from Isaca's CISM
Question #: 237
Topic #: 1
[All CISM Questions]

Which type of control is an incident response team?

  • A. Detective
  • B. Directive
  • C. Corrective
  • D. Preventive
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bambs
Highly Voted 1 year, 6 months ago
Selected Answer: A
Detective controls are designed to identify and detect security incidents or events that have already occurred or are in progress. An incident response team is responsible for detecting and responding to security incidents within an organization, making it a type of detective control.
upvoted 8 times
...
CISSPST
Highly Voted 1 year, 3 months ago
There is a difference between incident management and incident response. Incident management is actions taken prior to, during and after the incident. This includes pro-active and reactive detection of incidents. Incident response is actions taken when an incident has been declared, i.e. after detection and reporting. Among verification, assigning ownership, and triage this also includes corrective actions like containment, eradication and recovery. Therefore, the most likely answer is C, corrective.
upvoted 6 times
...
Chaser
Most Recent 5 months, 1 week ago
Its literally called incident response. Something happens then a response just like corrective control. Its C
upvoted 1 times
...
afoo1314
6 months, 4 weeks ago
Selected Answer: C
I thought detective is part of the NOC or SOC team. When incident detected and require escalation, which might trigger IRT to be involved.
upvoted 1 times
...
yottabyte
7 months, 1 week ago
Selected Answer: C
Its a corrective control and not detective control. Question is about Incident RESPONSE team.
upvoted 2 times
...
blehbleh
9 months, 2 weeks ago
Selected Answer: C
I'm going corrective. Reason being they are notified after an incident has taken place. Therefore, they aren't preventing it, detecting it or what ever the other option was. They come in after it has already been decided there is an incident to work. Yes, they detect whatever ever it is afterward but the team as a whole is not put in place to detect I would think that would fall under an IDS or IPS and then the team gets called into action afterward as the corrective control.
upvoted 2 times
blehbleh
9 months, 1 week ago
It literally has response in the name, hence corrective. They RESPOND to an incident.
upvoted 1 times
...
...
SpaceMonkey1
9 months, 3 weeks ago
Stupid Question. It is both Detective and corrective.
upvoted 2 times
SpaceMonkey1
9 months, 3 weeks ago
incident response teams encompass both detective (identifying and analyzing incidents) and corrective (taking actions to contain, eradicate, and recover from incidents) controls. Their activities involve not only detecting incidents but also responding to and correcting the impact of those incidents, making them a combination of detective and corrective controls.
upvoted 1 times
...
cidigi
6 months, 2 weeks ago
Based on CISA CRM 27 edition, Figure 1.5: Incident Response is Corrective.
upvoted 1 times
...
...
killainc
10 months, 2 weeks ago
An incident response team is a detective control. Detective controls are designed to identify and respond to security incidents after they have occurred. The incident response team's role is to detect, analyze, and mitigate security incidents in real-time or after they have occurred, working to minimize the impact and prevent future occurrences.
upvoted 1 times
...
Soleandheel
11 months ago
Guys please don't blindly listen to Chatgpt. I see that many of you here just accept whatever chatgpt provides as an answer but unfortunately many chatgpt answers are flawed. For this question chatgpt said A. Detective as the correct answer, but when i challenged it with supporting data from ISACA training, it apologized and changed it's answer to C. Corrective. This one is a nullbrainer. Don't blindly listen to chatgpt. Use your mind and do your own research.
upvoted 4 times
...
oluchecpoint
1 year, 1 month ago
A. Detective In the context of an incident response team, their primary role is to detect and respond to security incidents or breaches that have already taken place.
upvoted 1 times
oluchecpoint
1 year, 1 month ago
IRT will be call upon when an incident has been confirm, logical it is first detect follow by correction
upvoted 1 times
...
...
AomineDaiki
1 year, 2 months ago
IRTs are activated after an incident has been confirmed as true.
upvoted 1 times
...
[Removed]
1 year, 2 months ago
Selected Answer: C
According to the ISACA's CISM Review Manual, 27th Edition, an incident response team is a type of corrective control.
upvoted 3 times
...
Sammy65
1 year, 2 months ago
c: el equipo de respuesta a incidentes entra a corregir y no a detectar.
upvoted 1 times
...
Goseu
1 year, 2 months ago
Selected Answer: C
Trust me , C corrective .
upvoted 4 times
...
jennarink13
1 year, 3 months ago
C. Corrective. Main objective of incident management is to restore the affected processes back to its normal state as quickly as possible, minimizing the impact on the business, and NOT to detect incidents.
upvoted 2 times
...
Jae_kes
1 year, 4 months ago
Selected Answer: C
C. Corrective
upvoted 4 times
...
richck102
1 year, 4 months ago
A. Detective
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago