Objective 2.3CC

2.3 Understand incident response.

Objective 2.3 sits in Business Continuity, DR, and Incident Response, which carries 10% of the Certified in Cybersecurity exam. The questions below are original, written from the official objective title above, and each explanation cites the ISC2 page it rests on.

Objective title verbatim from the official objectives. ISC2 exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-3Business Continuity, DR, and Incident ResponseEasy

Under FISMA's definition, what turns an occurrence into an incident?

Occurring outside business hoursThe clock has nothing to do with the definition.
Generating any firewall log entryLogs record events all day; almost none meet the definition.
Involving an external IP addressPlenty of incidents are wholly internal.
Jeopardizing CIA or violating policyCorrect · your answerCorrect. Jeopardy to CIA or a policy violation is the defining line.

Correct.

Concept

Not every observable event is an incident; the label attaches when harm to security properties is actual or imminent, or when rules meant to protect them are broken.

Why D

FISMA defines an incident as an occurrence that actually or imminently jeopardizes integrity, confidentiality, or availability, or violates law, security policies, procedures, or acceptable use policies.

#incident-response#definitions

Now you: objective 2.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-3Business Continuity, DR, and Incident ResponseModerate

An agency's SOC team confirms a system compromise at 09:00. By when must CISA be notified?

Sample question 2 of 3

2-3Business Continuity, DR, and Incident ResponseModerate

One hour after detection, the response team still lacks validated details. What should it do about the report?

Sample question 3 of 3

2-3Business Continuity, DR, and Incident ResponseModerate

Which trio of impact classifications does an incident notification require?

Full Certified in Cybersecurity question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Business Continuity, DR, and Incident Response