Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 303 discussion

Actual exam question from ISC's CISSP
Question #: 303
Topic #: 1
[All CISSP Questions]

During testing, where are the requirements to inform parent organizations, law enforcement, and a computer incident response team documented?

  • A. Security Assessment Report (SAR)
  • B. Security assessment plan
  • C. Unit test results
  • D. System integration plan
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gautamzone
Highly Voted 2 years ago
Selected Answer: B
Document Name: TECHNICAL GUIDE TO INFORMATION SECURITY TESTING AND ASSESSMENT Ref URL: https://www.govinfo.gov/content/pkg/GOVPUB-C13-894df23cbad6ad74af7d49c17b081dd1/pdf/GOVPUB-C13-894df23cbad6ad74af7d49c17b081dd1.pdf Ref Page 52 Ref Text: Any requirements to inform parent organizations, law enforcement, and a computer incident response team (CIRT) should be identified in the assessment plan.
upvoted 6 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
user009
Highly Voted 1 year, 8 months ago
The correct answer is B. Security assessment plan. Explanation: The security assessment plan is a document that outlines the scope, objectives, and methodology of a security assessment, including testing activities. It typically includes details about what actions need to be taken in the event of a security incident, such as informing parent organizations, law enforcement, and computer incident response teams. This plan helps to ensure that all parties involved are aware of their responsibilities and that appropriate communication channels are in place. Incorrect answers: A. Security Assessment Report (SAR): The SAR is a document that presents the findings of a security assessment, including identified vulnerabilities and recommendations for mitigation. It does not typically contain information about informing relevant parties during testing.
upvoted 5 times
...
Soleandheel
Most Recent 11 months, 2 weeks ago
B. Security assessment plan. The Security Assessment Plan outlines the scope, objectives, methodology, and communication procedures for the security assessment, including incident reporting and notification protocols. It is different from a SAR report which is a report that shows the outcome or results of a security assessment.
upvoted 1 times
...
HappyDay030303
1 year ago
Selected Answer: B
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf "Any requirements to inform parent organizations, law enforcement, and a computer incident response team (CIRT) should be identified in the assessment plan"
upvoted 1 times
...
BoyBastos
1 year, 2 months ago
Selected Answer: B
A security assessment plan outlines the scope, objectives, and procedures for a security assessment. It also typically includes details about communication protocols, including when and how to inform relevant parties such as parent organizations, law enforcement, and computer incident response teams in the event of specific findings or incidents during the assessment. The other options do not typically contain this specific information.
upvoted 2 times
...
DASH_v
1 year, 6 months ago
B.The plan should also address the logistical details of the engagement—including the hours of operation for assessors; the clearance or background check level required; a call plan with current contact information, network and security operations centers, and the organization’s main point of contact for the assessment; the physical location where assessment activities will originate; and the equipment and tools that will be used to conduct the assessment. Any requirements to inform parent organizations, law enforcement, and a computer incident response team (CIRT) should be identified in the assessment plan. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
upvoted 1 times
...
Dee83
1 year, 10 months ago
A. Security Assessment Report (SAR)
upvoted 1 times
...
827
1 year, 10 months ago
Selected Answer: B
Any requirements to inform parent organizations, law enforcement, and a computer incident response team (CIRT) should be identified in the assessment plan.
upvoted 1 times
...
franbarpro
2 years, 1 month ago
Security Assessment Report - Provides a disciplined and structured approach for documenting the findings of the assessor and the recommendations for correcting any identified vulnerabilities in the security controls.
upvoted 3 times
...
saleem4u
2 years, 1 month ago
It should be SAP
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...