CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

An organization gathers department heads and IT leadership in a conference room to walk through a simulated ransomware scenario, discussing decisions and communication steps without performing any actual technical actions. Which activity is being conducted?

  1. APenetration test
  2. BRed team exercise
  3. CFull-scale disaster recovery test
  4. DTabletop exercise
Show answer & explanation

Correct answer: D. Tabletop exercise

A tabletop exercise is a discussion-based simulation where stakeholders talk through their roles and responses to a hypothetical incident without performing live technical actions.

Why the other options are wrong

  • A. A penetration test involves actively attempting to exploit systems, not discussion only.
  • B. A red team exercise simulates a real attack with actual technical activity against the environment.
  • C. A full-scale test involves actually executing recovery procedures, not just discussion.

Tabletop Exercise

A discussion-based exercise where stakeholders walk through their roles and responses to a simulated incident without performing live technical actions.

  • Low-cost, low-risk way to test incident response plans
  • Involves discussion, not actual system changes
  • Contrasts with full-scale/live simulations that execute real actions

Memory trick: Tabletop = talking around the table, not touching the tech.

More Security Program Management and Oversight questions