Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A security auditor is reviewing an organization's incident response plan. The plan outlines specific steps for detecting, analyzing, containing, eradicating, recovering from, and post-incident activities after a security breach. This structured approach is a key component of which security program element?
- ARisk Management
- BVulnerability Management
- CIncident Response
- DSecurity Awareness Training
Show answer & explanationAnswer & explanation
Correct answer: C. Incident Response
The scenario explicitly describes the phases of handling a security breach, from detection to recovery and follow-up. This entire process is the core definition of Incident Response, a critical element of any security program.
Why the other options are wrong
- A. Risk Management identifies, assesses, and mitigates risks, which is broader than just responding to incidents.
- B. Vulnerability Management identifies and remediates weaknesses before an attack, which is proactive, not reactive incident handling.
- D. Security Awareness Training educates employees to prevent incidents, not to handle them once they occur.
Incident Response
A structured and organized approach to addressing and managing the aftermath of a security breach or cyberattack.
- Aims to minimize damage and recovery time.
- Follows a defined lifecycle (preparation, detection, containment, eradication, recovery, post-incident).
- Crucial for business continuity and reputation.
Memory trick: Program elements: Manage risks, Respond to incidents, Train people, Patch vulnerabilities.