CSL Incident Response & Crisis Management 2 — Questions and Answers
Question 1: During a large-scale ransomware attack, the CISO must decide whether to pay the ransom. Which factor should MOST influence this decision?
- The attacker's reputation for providing decryption keys after payment
- Whether paying complies with OFAC sanctions regulations and legal obligations (Correct answer)
- The total ransom amount relative to the organization's cyber insurance coverage
- How quickly the finance team can arrange a cryptocurrency transfer
Correct answer: Whether paying complies with OFAC sanctions regulations and legal obligations
Paying ransoms to sanctioned entities violates OFAC regulations and can result in severe civil penalties, making legal compliance the primary decision factor.
Question 2: Which metric BEST measures the effectiveness of an incident response team's performance over time?
- Number of security tools deployed during incidents
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends (Correct answer)
- Total headcount of the incident response team
- Number of incidents escalated to law enforcement
Correct answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends
MTTD and MTTR trends directly reflect the IR team's ability to identify and contain threats faster over successive incidents.
Question 3: A zero-day vulnerability is actively exploited in your environment before a patch is available. What is the MOST appropriate immediate leadership action?
- Wait for the vendor to release an official patch before taking action
- Publicly disclose the vulnerability to warn industry peers
- Activate crisis management protocols and implement compensating controls (Correct answer)
- Shut down all internet-facing systems until the patch is released
Correct answer: Activate crisis management protocols and implement compensating controls
Activating crisis protocols and deploying compensating controls (network segmentation, enhanced monitoring, WAF rules) limits exposure while a patch is pending.
Question 4: During a crisis, the board of directors requests real-time updates every 30 minutes. How should the CISO respond to this demand?
- Comply fully and dedicate a team member solely to board communications
- Ignore the request and focus entirely on technical remediation
- Negotiate a structured briefing schedule that avoids distracting the response team (Correct answer)
- Delegate all board communications to the legal department
Correct answer: Negotiate a structured briefing schedule that avoids distracting the response team
A structured briefing schedule keeps stakeholders informed without pulling critical responders off containment and eradication tasks.
Question 5: What does the concept of 'tabletop exercise' primarily test in the context of incident response?
- The technical capabilities of security tools under load
- Decision-making, communication, and coordination among stakeholders without simulating real systems (Correct answer)
- The speed of automated playbook execution during an attack
- Physical security controls at data center facilities
Correct answer: Decision-making, communication, and coordination among stakeholders without simulating real systems
Tabletop exercises are discussion-based sessions that evaluate people, processes, and decision-making rather than live technical systems.
Question 6: An insider threat is suspected of exfiltrating customer data. Which action should be taken FIRST to preserve evidence while minimizing operational disruption?
- Immediately terminate the employee's access and delete their accounts
- Coordinate with HR and legal to covertly monitor activity and preserve forensic evidence (Correct answer)
- Alert the employee that they are under investigation to give them a chance to explain
- Shut down the suspected employee's workstation without imaging it
Correct answer: Coordinate with HR and legal to covertly monitor activity and preserve forensic evidence
Coordinating with HR and legal for covert monitoring preserves evidence integrity and avoids tipping off the suspect or compromising the investigation.
Question 7: Which framework specifically defines a five-function approach (Identify, Protect, Detect, Respond, Recover) applicable to structuring incident response programs?
- ISO/IEC 27035
- NIST Cybersecurity Framework (CSF) (Correct answer)
- SANS IR Lifecycle
- COBIT 2019
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework organizes security activities into five core functions: Identify, Protect, Detect, Respond, and Recover.
During a large-scale ransomware attack, the CISO must decide whether to pay the ransom.
Which factor should MOST influence this decision?