PECB Certified ISO/IEC 27001 : 2022 Lead Implementer exam ISO-IEC-27001-Lead-Implementer Question # 72 Topic 8 Discussion

PECB Certified ISO/IEC 27001 : 2022 Lead Implementer exam ISO-IEC-27001-Lead-Implementer Question # 72 Topic 8 Discussion

ISO-IEC-27001-Lead-Implementer Exam Topic 8 Question 72 Discussion:
Question #: 72
Topic #: 8

Scenario 7: Incident Response at Texas H&H Inc.

Once they made sure that the attackers do not have access in their system, the security administrators decided to proceed with the forensic analysis. They concluded that their access security system was not designed tor threat detection, including the detection of malicious files which could be the cause of possible future attacks.

Based on these findings. Texas H$H inc, decided to modify its access security system to avoid future incidents and integrate an incident management policy in their Information security policy that could serve as guidance for employees on how to respond to similar incidents.

Based on the scenario above, answer the following question:

According to scenario 7, the team prevented a potential attack based on knowledge gained from previous incidents. Is this acceptable?


A.

No, before responding to an information security incident, an information security incident management policy must be established


B.

No, every information security incident is different, hence knowledge gained from previous incidents cannot prevent potential attacks


C.

Yes, in the absence of an information security incident management policy, lessons learned can be applied


Get Premium ISO-IEC-27001-Lead-Implementer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.