Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 137 discussion

Actual exam question from ISC's CISSP
Question #: 137
Topic #: 1
[All CISSP Questions]

What is the PRIMARY benefit of incident reporting and computer crime investigations?

  • A. Complying with security policy
  • B. Repairing the damage and preventing future occurrences
  • C. Providing evidence to law enforcement
  • D. Appointing a computer emergency response team
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
kasiya
Highly Voted 2 years, 2 months ago
Selected Answer: B
benefit! only B
upvoted 11 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
Meowson
1 year, 4 months ago
Stop giving out meaningless reply without supporting reason.
upvoted 10 times
...
...
...
Rachy
Most Recent 3 months, 1 week ago
Selected Answer: B
All answers should always point to objective of the business. Would your answer benefit the business as a Ceo?
upvoted 1 times
...
pete79
9 months, 3 weeks ago
Selected Answer: A
A: Incident reporting can be part of policy, however not every reported incident is required by law enforcers as there might not be an investigation
upvoted 1 times
...
gjimenezf
10 months, 2 weeks ago
Selected Answer: B
prevent from happening again is more important than provide evidence otherwise you will provide evidence multiple times and lower the trust in your company
upvoted 1 times
...
Vince_F_Fang
1 year ago
Selected Answer: C
C. Setting aside the company's responsibilities, preventing unnecessary litigation, and investigating can also prevent future incidents from happening again
upvoted 2 times
...
Moose01
1 year ago
A. it is A, an Incident is different then an accident - Incident has no damage where accident has damages... all incidents must be documented per Organization set policies.
upvoted 1 times
...
LalithW
1 year, 1 month ago
Selected Answer: C
Incident reporting and crime investigation provide evidence to law enforcement. Lessons learned support preventing future occurrences, which has not been mentioned here.
upvoted 1 times
...
williom
1 year, 1 month ago
I think it’s B, thinking like a manager. - Primary benefit to the organisation, B. Primary benefit to society, C
upvoted 2 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: B
The PRIMARY benefit of incident reporting and computer crime investigations is B: "Repairing the damage and preventing future occurrences". Incident reporting helps to identify and analyze security incidents, and computer crime investigations help to determine the cause of the incident and take steps to prevent it from happening again in the future. While complying with security policy, providing evidence to law enforcement, and appointing a computer emergency response team are important, they are not the primary benefit of incident reporting and computer crime investigations. Providing evidence to law enforcement is an important benefit of incident reporting and computer crime investigations, but it is not the primary benefit because the main focus of incident reporting and computer crime investigations is to repair the damage and prevent future occurrences.
upvoted 2 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
the PRIMARY benefit can be considered as C. Providing evidence to law enforcement. providing evidence to law enforcement is an important benefit of incident reporting and computer crime investigations. While repairing the damage and preventing future occurrences is also a significant benefit, the ability to provide evidence to law enforcement can contribute to the identification, apprehension, and prosecution of individuals involved in computer crimes. It helps in holding perpetrators accountable for their actions and deterring future criminal activity.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
I am going with B. An incident report can be anything, like a drive that failed, or a server that crashed, etc. So that needs to be repaired. That's the benefit of an incident report, that the problem will be fixed. Only B addresses repairing a crashed server. Now the confusing part is the crime investigation, but once you figure out how it happened it can be prevented in the future. Complaining to law enforcement is often pointless bc computer crimes are hard to prosecute since they don't have a clear jurisdiction and criminals are hard to catch. So B seems pretty solid, although C is a part of the answer.
upvoted 3 times
...
jbell
1 year, 6 months ago
Selected Answer: B
From CBK: All incidents should be investigated and remediated to restore the organization's normal operations as quickly as possible and to minimize impacts like lost productivity or revenue. Resuming normal service is the primary goal of incident management.
upvoted 4 times
jbell
1 year, 6 months ago
From NIST SP 800-61 Computer Security Incident Handling Guide: Although the primary reason for gathering evidence during an incident is to resolve the incident, it may also be needed for legal proceedings.
upvoted 1 times
...
...
BennyMao
1 year, 6 months ago
Selected Answer: B
By conducting investigations and reporting incidents, organizations can identify the root cause of the incident and take corrective action to prevent it from happening again. Additionally, incident reporting and investigations can help organizations to improve their security posture by identifying vulnerabilities and weaknesses in their security controls.
upvoted 1 times
...
Dee83
1 year, 10 months ago
C. Correct answer Providing evidence to law enforcement is the PRIMARY benefit of incident reporting and computer crime investigations. The primary goal of incident reporting and computer crime investigations is to collect evidence that can be used to identify and prosecute the individuals or organizations responsible for the crime. This may include identifying the methods used to gain unauthorized access, determining the extent of the damage caused, and identifying any sensitive data that may have been compromised. A. Complying with security policy is also important as it helps organizations to identify and report incidents as part of their compliance requirements and to meet the regulatory requirements. B. Repairing the damage and preventing future occurrences is a secondary goal. It can help to minimize the damage caused by the incident and prevent it from happening again in the future. D. Appointing a computer emergency response team (CERT) is an important step in incident response, CERT team can play a key role in identifying and responding to security incidents and to help organizations to recover from the incident.
upvoted 2 times
dumdada
1 year, 5 months ago
You're just copy/pasting ChatGPT on every question?
upvoted 1 times
...
...
Delab202
1 year, 10 months ago
Selected Answer: D
Policies drives what is an incident and reportable.
upvoted 1 times
Delab202
1 year, 10 months ago
option A
upvoted 1 times
...
...
somkiatr
1 year, 10 months ago
Selected Answer: C
C is correct. What is computer forensics? Computer forensics is the application of investigation and analysis techniques to gather and preserve evidence from a particular computing device in a way that is suitable for presentation in a court of law. reference: https://www.techtarget.com/searchsecurity/definition/computer-forensics
upvoted 1 times
...
rajkamal0
1 year, 11 months ago
Selected Answer: C
This is confusing question, the best answer is C.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...