CCISO Incident Management & Response 3 — Questions and Answers
Question 1: A financial institution experiences a breach affecting 100,000 customer records. Under US regulations, which regulatory body typically requires notification within a specific timeframe for this type of institution?
- FTC under the Health Breach Notification Rule
- Federal banking regulators under the GLBA Safeguards Rule notification requirements (Correct answer)
- EPA under environmental reporting rules
- OSHA under workplace safety regulations
Correct answer: Federal banking regulators under the GLBA Safeguards Rule notification requirements
Under the GLBA Safeguards Rule, financial institutions must notify their primary federal banking regulator as soon as possible within 36 hours of discovering a notification event.
Question 2: Which component of a business continuity plan most directly supports the incident response function during a major cyber event?
- Marketing communication templates
- Recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical systems (Correct answer)
- Employee performance review schedules
- Office lease agreements
Correct answer: Recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical systems
RTOs and RPOs define acceptable downtime and data loss thresholds, guiding IR prioritization decisions about which systems to restore first.
Question 3: A CISO wants to test whether the IR team can handle a simulated advanced persistent threat without disrupting production systems. Which exercise type is MOST appropriate?
- Full-scale live-fire exercise on production infrastructure
- Purple team exercise in an isolated lab environment (Correct answer)
- Annual policy review meeting
- Phishing awareness training campaign
Correct answer: Purple team exercise in an isolated lab environment
Purple team exercises in isolated environments allow realistic adversary simulation and IR testing without risking production system availability.
Question 4: When a security incident involves a third-party cloud provider, the CISO's incident response plan should address which unique challenge?
- Reduced need for forensic investigation
- Limited direct access to infrastructure and reliance on provider cooperation for evidence collection (Correct answer)
- Automatic regulatory exemption due to shared responsibility
- Elimination of notification obligations
Correct answer: Limited direct access to infrastructure and reliance on provider cooperation for evidence collection
In cloud environments, the organization often cannot directly access underlying infrastructure, making evidence collection dependent on the provider's cooperation and contractual SLAs.
Question 5: An attacker used compromised credentials obtained via credential stuffing to access a customer portal. After containment, which remediation action has the highest long-term impact on preventing recurrence?
- Resetting only the compromised accounts
- Implementing multi-factor authentication across all customer-facing portals (Correct answer)
- Blocking the attacker's IP addresses permanently
- Increasing password minimum length to 10 characters
Correct answer: Implementing multi-factor authentication across all customer-facing portals
MFA prevents credential stuffing attacks from succeeding even when valid credentials are obtained, addressing the root cause rather than symptoms.
Question 6: A CISO reviews the incident response team's post-incident report and notices that root cause analysis was skipped to meet reporting deadlines. What risk does this create?
- Increased legal liability for documenting the attack
- Failure to identify systemic vulnerabilities, increasing the likelihood of repeat incidents (Correct answer)
- Regulatory requirement to re-open the incident
- Automatic audit finding requiring a fine
Correct answer: Failure to identify systemic vulnerabilities, increasing the likelihood of repeat incidents
Skipping root cause analysis leaves underlying vulnerabilities unaddressed, making the organization susceptible to identical or similar attacks in the future.
Question 7: In the context of IR communications, what is the primary purpose of a crisis communication plan at the executive level?
- To train helpdesk staff on ticket escalation procedures
- To ensure consistent, accurate, and legally vetted messaging to stakeholders, regulators, and the public during an incident (Correct answer)
- To automate SIEM alert triage
- To define firewall rule change approval workflows
Correct answer: To ensure consistent, accurate, and legally vetted messaging to stakeholders, regulators, and the public during an incident
Executive crisis communication plans coordinate messaging across all stakeholder groups to prevent misinformation, manage reputational damage, and ensure legal compliance during incidents.
A financial institution experiences a breach affecting 100,000 customer records.
Under US regulations, which regulatory body typically requires notification within a specific timeframe for this type of institution?