Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A security auditor is reviewing an organization's incident response plan. The plan outlines specific steps for detecting, analyzing, containing, eradicating, recovering from, and post-incident activities after a security breach. This structured approach is a key component of which security program element?

  1. ARisk Management
  2. BVulnerability Management
  3. CIncident Response
  4. DSecurity Awareness Training
Show answer & explanation

Correct answer: C. Incident Response

The scenario explicitly describes the phases of handling a security breach, from detection to recovery and follow-up. This entire process is the core definition of Incident Response, a critical element of any security program.

Why the other options are wrong

  • A. Risk Management identifies, assesses, and mitigates risks, which is broader than just responding to incidents.
  • B. Vulnerability Management identifies and remediates weaknesses before an attack, which is proactive, not reactive incident handling.
  • D. Security Awareness Training educates employees to prevent incidents, not to handle them once they occur.

Incident Response

A structured and organized approach to addressing and managing the aftermath of a security breach or cyberattack.

  • Aims to minimize damage and recovery time.
  • Follows a defined lifecycle (preparation, detection, containment, eradication, recovery, post-incident).
  • Crucial for business continuity and reputation.

Memory trick: Program elements: Manage risks, Respond to incidents, Train people, Patch vulnerabilities.

More Security Principles questions