Which of the following describes how a csirt lead determines - CompTIA CySA+ CSO-003

Question

Which of the following describes how a CSIRT lead determines who should be communicated with and when during a security incident?

Answers
  1. correct
Explanation

The correct answer is: A. The lead should review what is documented in the incident response policy or plan

This is the correct answer because the incident response policy or plan outlines communication protocols, detailing who needs to be informed, when, and how. The CSIRT lead should follow these guidelines to ensure that communication is consistent and structured throughout the incident.

Why the Other Options Are Incorrect:

Management level members of the CSIRT should make that decision

  • This is incorrect because while management may be involved in strategic decisions, the day-to-day communication decisions are generally outlined in the incident response policy. The CSIRT lead manages the tactical aspects, including communication, based on the predefined plan.

The lead has the authority to decide who to communicate with at any time

  • This is incorrect because the CSIRT lead's communication decisions should be guided by the incident response plan, not made arbitrarily. Following the plan ensures that communication is appropriate and consistent with organizational protocols.

Subject matter experts on the team should communicate with others within the specified area of expertise

  • This is incorrect because while subject matter experts may provide detailed communication within their areas of expertise, the overall communication strategy is managed by the CSIRT lead. The lead ensures that the communication is coordinated and aligns with the broader response plan.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered