2.3 Understand incident response.
Objective 2.3 sits in Business Continuity, DR, and Incident Response, which carries 10% of the Certified in Cybersecurity exam. The questions below are original, written from the official objective title above, and each explanation cites the ISC2 page it rests on.
Objective title verbatim from the official objectives. ISC2 exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Under FISMA's definition, what turns an occurrence into an incident?
Correct.
Concept
Not every observable event is an incident; the label attaches when harm to security properties is actual or imminent, or when rules meant to protect them are broken.
Why D
FISMA defines an incident as an occurrence that actually or imminently jeopardizes integrity, confidentiality, or availability, or violates law, security policies, procedures, or acceptable use policies.
Now you: objective 2.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An agency's SOC team confirms a system compromise at 09:00. By when must CISA be notified?
Sample question 2 of 3
One hour after detection, the response team still lacks validated details. What should it do about the report?
Sample question 3 of 3
Which trio of impact classifications does an incident notification require?
Full Certified in Cybersecurity question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.