CCISO Incident Management & Response 4 — Questions and Answers
Question 1: A CISO is evaluating whether to outsource incident response to a managed security service provider (MSSP). Which factor represents the GREATEST risk of this arrangement?
- Higher cost compared to internal teams
- Potential loss of institutional knowledge and delayed response due to lack of organizational context (Correct answer)
- Inability to use SIEM tools
- Reduced need for tabletop exercises
Correct answer: Potential loss of institutional knowledge and delayed response due to lack of organizational context
MSSPs may lack deep organizational context, which can slow investigation and remediation when incidents involve specific business processes or custom systems.
Question 2: Which of the following BEST describes the role of threat intelligence in the incident response lifecycle?
- Replacing the need for forensic analysis
- Enriching detection and providing adversary context to accelerate investigation and improve containment decisions (Correct answer)
- Automating all containment actions without human review
- Fulfilling regulatory reporting requirements automatically
Correct answer: Enriching detection and providing adversary context to accelerate investigation and improve containment decisions
Threat intelligence provides indicators of compromise and adversary TTPs that accelerate identification, scope assessment, and informed containment during incident response.
Question 3: An insider threat incident is discovered involving a privileged administrator who copied sensitive data to personal cloud storage over six months. Which IR process failure allowed the prolonged activity?
- Absence of a vulnerability management program
- Lack of user and entity behavior analytics (UEBA) or privileged user monitoring controls (Correct answer)
- Failure to conduct annual security awareness training
- Missing patch management procedures
Correct answer: Lack of user and entity behavior analytics (UEBA) or privileged user monitoring controls
UEBA and privileged user monitoring detect anomalous behavior patterns over time, which are necessary to catch slow-burn insider threats that evade signature-based detection.
Question 4: During incident containment, the IR team isolates an infected endpoint by removing it from the network. This action is BEST classified as which type of containment?
- Long-term containment with remediation
- Short-term containment to limit immediate spread (Correct answer)
- Eradication phase activity
- Recovery phase restoration
Correct answer: Short-term containment to limit immediate spread
Network isolation of an infected endpoint is a short-term containment measure that limits the immediate spread of an incident while investigation and eradication planning proceed.
Question 5: A CISO must decide how long to retain incident-related logs and forensic artifacts. Which factor should MOST influence this retention period?
- Available storage capacity only
- Legal hold requirements, regulatory mandates, and statute of limitations for potential litigation (Correct answer)
- IT department preference for data minimization
- Marketing analytics needs
Correct answer: Legal hold requirements, regulatory mandates, and statute of limitations for potential litigation
Legal holds, regulatory requirements, and litigation timelines dictate minimum retention periods for incident artifacts to ensure evidence availability for legal and compliance purposes.
Question 6: Which of the following BEST describes the difference between an incident response plan (IRP) and a disaster recovery plan (DRP) from a CISO's perspective?
- IRPs focus on restoring IT systems while DRPs address security events
- IRPs address security event detection, containment, and eradication while DRPs focus on restoring business operations after major disruptions (Correct answer)
- IRPs are optional while DRPs are mandated by all regulations
- IRPs cover physical disasters while DRPs cover cyber events
Correct answer: IRPs address security event detection, containment, and eradication while DRPs focus on restoring business operations after major disruptions
IRPs govern the security response lifecycle (detect, contain, eradicate) while DRPs focus on restoring business operations and IT systems after a disruptive event, including cyber incidents.
Question 7: A CISO receives a threat intelligence report indicating that a nation-state actor is actively targeting organizations in their industry using a specific zero-day vulnerability. What is the MOST appropriate immediate IR preparedness action?
- Wait for the vendor to release a patch before taking action
- Activate threat hunting operations to search for indicators of compromise and increase monitoring sensitivity for related TTPs (Correct answer)
- Disclose the threat publicly to warn competitors
- Shut down all external-facing systems indefinitely
Correct answer: Activate threat hunting operations to search for indicators of compromise and increase monitoring sensitivity for related TTPs
Proactive threat hunting and increased monitoring sensitivity allow early detection of nation-state intrusion attempts even before patches are available for zero-day vulnerabilities.
A CISO is evaluating whether to outsource incident response to a managed security service provider (MSSP).
Which factor represents the GREATEST risk of this arrangement?