An employees device was missing for 96 hours before being re - CompTIA CAS-005

Question

An employee's device was missing for 96 hours before being reported. The employee called the help desk to ask for another device. Which of the following phases of the incident response cycle needs improvement?

Answers
  1. correct
Explanation

The correct answer is: B. Preparation

The Preparation phase of the incident response cycle involves implementing policies, procedures, and training to ensure that employees and systems are ready to respond to incidents effectively. In this scenario, the delay of 96 hours before reporting the missing device indicates a lack of clear reporting procedures, insufficient training, or inadequate awareness of security protocols.

To improve the preparation phase:

  • Train employees on the importance of reporting lost or stolen devices immediately.
  • Establish clear policies for reporting security incidents.
  • Ensure employees understand the potential risks of delayed reporting, such as data breaches or unauthorized access.

Why the other options are incorrect:

Containment:

  • Incorrect: Containment involves stopping the spread of an incident once it is identified. The issue here occurred before the incident was reported, indicating that preparation, not containment, is the problem.

Resolution:

  • Incorrect: Resolution refers to resolving the incident and restoring normal operations. The problem lies in the delay of reporting, which occurs before resolution activities.

Investigation:

  • Incorrect: Investigation involves determining the root cause and impact of the incident after it has been reported. The delay in reporting suggests a failure in preparation, not the investigation phase.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered