CompTIA Security+ (SY0-701)Security OperationsEasy

A company wants to test its incident response plan without impacting live systems by having stakeholders discuss their roles during a simulated ransomware scenario. Which exercise type is being described?

  1. APenetration test
  2. BVulnerability scan
  3. CTabletop exercise
  4. DRed team engagement
Show answer & explanation

Correct answer: C. Tabletop exercise

A tabletop exercise is a discussion-based session where stakeholders walk through their responsibilities during a simulated incident, without affecting production systems.

Why the other options are wrong

  • A. A penetration test actively attempts to exploit systems, unlike a discussion-based exercise.
  • B. A vulnerability scan identifies weaknesses, not response coordination.
  • D. Red team engagements involve active adversarial simulation on live systems.

Tabletop Exercise

A discussion-based simulation where team members review and practice their roles in a hypothetical incident scenario.

  • Low-cost, low-risk training method
  • Identifies gaps in IR plans and communication
  • Does not involve technical system changes

Memory trick: Talk it through at the table first.

More Security Operations questions