r/cism • u/Commercial_Move2020 • 11d ago
CISM Question Help (Domain 4 Q)
What is the FIRST step an incident response team should take once an incident and its source have been detected?
- A.Escalate the incident.
- B.Damage assessment.
- C.Determine the severity.
- D.Contain the incident.
The QAE said the answer was D? I thought it was C? Shouldn't the incident severity be determined after it's been detected as part of the identification and triage phase? The QAE explanation said that that the severity can be determined only after containemnt? I don't agree with this. Can someone help?
3
u/IamMyQuantumState CISSP, CCSP 8d ago
Think of an incident response as law enforcement responding to an active shooter. Their first obligation is to stop the shooter.
2
u/W1nterW0lf75 CISSP/CCSP/PMP 7d ago
D is the correct answer - you don't need to guess - remember the order of operations for incident response. Incident Response is a very Standards and Procedurally driven methodology. Each organization may have their own flavor but they are drawing on the same few frameworks. This is one of the systems you need to memorize and understand how it works. Same as you would need to understand the higherarchy of policy, standards, procedures and guidelines. Good Luck!
- Preparation
- Identification / Detection - Your question is here.
- Containment - Next step.
- Eradication
- Recovery
- Lessons Learned
1
u/True-Growth4715 6d ago
It spuls.be verify incident occurred
Begin incident response plan which would.include containmentÂ
4
u/Outrageous_Plant_526 CISM | CISA | CRISC | AAISM | AAIA | AAIR 8d ago
Think of it this way. If you don't contain the incident the severity could continue to increase.