The FIRST step in an incident response plan is to:
A.
validate the incident.
B.
notify the head of the IT department.
C.
isolate systems impacted by the incident.
D.
initiate root cause analysis.
The Answer Is:
A
This question includes an explanation.
Explanation:
The first step in an incident response plan is typically preparation12. However, among the options provided, validating the incident would be the first step. This involves confirming that a security event is actually an incident3. It’s important to verify the event to avoid wasting resources on false positives.
[References:, Incident Response Plan: Frameworks and Steps - CrowdStrike, What is Incident Response? Plan and Steps | Microsoft Security, What Are the Phases of an Incident Response Plan? - ISC2 Blog, , , , , , , ]
CISA PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 75% Discount on All Products,
Use Coupon: "ac75sure"