Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard

A security operations center (SOC) receives an alert indicating unusual outbound network traffic from an internal server to an unknown external IP address. The SOC team immediately initiates their defined incident response procedure, which includes verifying the alert, isolating the server, and collecting forensic images. This systematic approach, driven by a pre-defined set of actions for specific types of security events, best exemplifies the organization's commitment to which security concept?

  1. AProactive threat hunting
  2. BIncident response maturity
  3. CVulnerability management
  4. DContinuous monitoring
Show answer & explanation

Correct answer: B. Incident response maturity

A systematic approach to incident response, with predefined procedures and immediate actions, demonstrates a high level of 'incident response maturity', indicating a well-developed and effective incident response capability.

Why the other options are wrong

  • A. Proactive threat hunting is about actively searching for threats, not reacting to an alert with defined steps.
  • C. Vulnerability management is about identifying and patching weaknesses, not responding to active threats.
  • D. Continuous monitoring is the detection aspect, but the scenario emphasizes the *reaction* to the alert.

Incident Response Maturity

The level of an organization's capability to effectively and efficiently detect, analyze, contain, eradicate, and recover from security incidents.

  • Ranges from ad-hoc (low maturity) to optimized (high maturity).
  • Characterized by documented plans, skilled teams, and regular practice.
  • Assessed using frameworks like CMMI or NIST's IR maturity model.

Memory trick: Maturity shows how well we DO, PLAN, and ADAPT.

More Security Policies and Procedures questions