CompTIA Security+ (SY0-701)Security OperationsEasy
A company wants to test its incident response plan without impacting live systems by having stakeholders discuss their roles during a simulated ransomware scenario. Which exercise type is being described?
- APenetration test
- BVulnerability scan
- CTabletop exercise
- DRed team engagement
Show answer & explanationAnswer & explanation
Correct answer: C. Tabletop exercise
A tabletop exercise is a discussion-based session where stakeholders walk through their responsibilities during a simulated incident, without affecting production systems.
Why the other options are wrong
- A. A penetration test actively attempts to exploit systems, unlike a discussion-based exercise.
- B. A vulnerability scan identifies weaknesses, not response coordination.
- D. Red team engagements involve active adversarial simulation on live systems.
Tabletop Exercise
A discussion-based simulation where team members review and practice their roles in a hypothetical incident scenario.
- Low-cost, low-risk training method
- Identifies gaps in IR plans and communication
- Does not involve technical system changes
Memory trick: Talk it through at the table first.