A soc manager receives a phone call from an upset customer t - CompTIA CySA+ CSO-003

Question

A SOC manager receives a phone call from an upset customer. The customer received a vulnerability report two hours ago: but the report did not have a follow-up remediation response from an analyst. Which of the following documents should the SOC manager review to ensure the team is meeting the appropriate contractual obligations for the customer?

Answers
  1. correct
Explanation

The correct answer is: A. SLA

This is the correct answer because an SLA (Service Level Agreement) outlines the specific performance metrics, such as response times and the level of service expected between a service provider and a customer. The SLA typically includes the expected timelines for actions like providing remediation responses after receiving a vulnerability report. By reviewing the SLA, the SOC manager can confirm whether the team is meeting the contractual obligations regarding response times and remediation, ensuring they fulfill their responsibilities as agreed with the customer.

Why the Other Options Are Incorrect:

MOU

  • This is incorrect because an MOU (Memorandum of Understanding) is a document that outlines a mutual agreement or understanding between parties but is not legally binding like an SLA. It generally does not specify detailed service expectations or performance metrics such as response times or remediation actions for cybersecurity incidents.

NDA

  • This is incorrect because an NDA (Non-Disclosure Agreement) is designed to protect confidential information shared between parties. It does not typically include service-related commitments such as response times or remediation procedures, which are crucial for ensuring that the customer’s expectations are met.

Limitation of liability

  • This is incorrect because the Limitation of Liability clause usually outlines the extent of liability that a company is responsible for in the event of an issue or breach. While important for understanding potential legal exposure, it does not specify service levels, response times, or obligations related to customer communications, like providing remediation responses after a vulnerability report.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered