CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
An organization gathers department heads and IT leadership in a conference room to walk through a simulated ransomware scenario, discussing decisions and communication steps without performing any actual technical actions. Which activity is being conducted?
- APenetration test
- BRed team exercise
- CFull-scale disaster recovery test
- DTabletop exercise
Show answer & explanationAnswer & explanation
Correct answer: D. Tabletop exercise
A tabletop exercise is a discussion-based simulation where stakeholders talk through their roles and responses to a hypothetical incident without performing live technical actions.
Why the other options are wrong
- A. A penetration test involves actively attempting to exploit systems, not discussion only.
- B. A red team exercise simulates a real attack with actual technical activity against the environment.
- C. A full-scale test involves actually executing recovery procedures, not just discussion.
Tabletop Exercise
A discussion-based exercise where stakeholders walk through their roles and responses to a simulated incident without performing live technical actions.
- Low-cost, low-risk way to test incident response plans
- Involves discussion, not actual system changes
- Contrasts with full-scale/live simulations that execute real actions
Memory trick: Tabletop = talking around the table, not touching the tech.