Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

An organization is developing its cybersecurity incident response plan. A key component of the plan involves defining clear roles and responsibilities for the incident response team and establishing communication channels for reporting and escalating incidents. Which security program element is this organization primarily focusing on?

  1. AIncident Response
  2. BSecurity Policy
  3. CRisk Assessment
  4. DSecurity Auditing
Show answer & explanation

Correct answer: A. Incident Response

The scenario directly describes the development of an incident response plan, focusing on team roles, responsibilities, and communication channels for handling security incidents. This is the core of an Incident Response program.

Why the other options are wrong

  • B. Security Policy sets rules and guidelines, which is broader than just incident handling.
  • C. Risk Assessment identifies potential threats and vulnerabilities, which informs incident response but isn't the plan itself.
  • D. Security Auditing reviews controls and compliance, which is distinct from responding to live incidents.

Incident Response

The organized approach an organization takes to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage and reduces recovery time and costs.

  • Follows a structured lifecycle (e.g., NIST SP 800-61).
  • Involves preparation, detection & analysis, containment, eradication & recovery, post-incident activity.
  • Requires clear roles, communication, and documentation.

Memory trick: Security program needs: policies to guide, assessments to know risks, response for when things go wrong.

More Security Principles questions