<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clarification on Quiz question Domain 2: Incident management in CC Study Group</title>
    <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73688#M2833</link>
    <description>&lt;P&gt;If you think the question/answer are incorrect, you should let Exam Administration know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, I believe the answer provided "Assessing and Scoping" is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my part, I believe this is a terrible question with two of the answers being throw aways such that the candidate has a 50/50 chance of getting it right or wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference, if you look at NIST (great references), you will find:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;NIST incident response lifecycle breaks incident response down into four main phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Event Activity.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 1: Preparation&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;The Preparation phase covers the work an organization does to get ready for incident response, including establishing the right tools and resources and training the team. This phase includes work done to prevent incidents from happening.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 2: Detection and Analysis&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;Accurately detecting and assessing incidents is often the most difficult part of incident response for many organizations, according to NIST.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 3: Containment, Eradication, and Recovery&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;This phase focuses on keeping the incident impact as small as possible and mitigating service disruptions.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 4: Post-Event Activity&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;Learning and improving after an incident is one of the most important parts of incident response and the most often ignored. In this phase the incident and incident response efforts are analyzed. The goals here are to limit the chances of the incident happening again and to identify ways of improving future incident response activity.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 09 Sep 2024 13:43:08 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2024-09-09T13:43:08Z</dc:date>
    <item>
      <title>Clarification on Quiz question Domain 2: Incident management</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73680#M2827</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have completed&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Domain 2: Incident Response, BCP, DR and I was wondering about this question:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Winny_0-1725876138961.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9033i0C8B102BB8B6E3EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Winny_0-1725876138961.png" alt="Winny_0-1725876138961.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;If the Incident response team is responsible for assessing the damage, then who is responsible for reducing the impact of incidents?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 10:04:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73680#M2827</guid>
      <dc:creator>Winny</dc:creator>
      <dc:date>2024-09-09T10:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Quiz question Domain 2: Incident management</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73682#M2828</link>
      <description>&lt;P&gt;With a continuity incident you could only really reduce the impact through having prepared for a business interruption.&amp;nbsp; So if you had east/west power from 2 different substations, 3 backup generator sets, arrangements to refuel them if necessary, dual data ingress to a facility etc.&amp;nbsp; those are only things that you can do in advance, rather than as response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 12:08:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73682#M2828</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2024-09-09T12:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Quiz question Domain 2: Incident management</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73686#M2832</link>
      <description>&lt;P&gt;Actually in other advanced ISC2 exam, it's often that every multi-choice question has 2 or more correct answers. You have to choose the most suitable one.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 13:06:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73686#M2832</guid>
      <dc:creator>JacobLin</dc:creator>
      <dc:date>2024-09-09T13:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Quiz question Domain 2: Incident management</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73688#M2833</link>
      <description>&lt;P&gt;If you think the question/answer are incorrect, you should let Exam Administration know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, I believe the answer provided "Assessing and Scoping" is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my part, I believe this is a terrible question with two of the answers being throw aways such that the candidate has a 50/50 chance of getting it right or wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference, if you look at NIST (great references), you will find:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;NIST incident response lifecycle breaks incident response down into four main phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Event Activity.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 1: Preparation&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;The Preparation phase covers the work an organization does to get ready for incident response, including establishing the right tools and resources and training the team. This phase includes work done to prevent incidents from happening.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 2: Detection and Analysis&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;Accurately detecting and assessing incidents is often the most difficult part of incident response for many organizations, according to NIST.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 3: Containment, Eradication, and Recovery&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;This phase focuses on keeping the incident impact as small as possible and mitigating service disruptions.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;EM&gt;Phase 4: Post-Event Activity&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;Learning and improving after an incident is one of the most important parts of incident response and the most often ignored. In this phase the incident and incident response efforts are analyzed. The goals here are to limit the chances of the incident happening again and to identify ways of improving future incident response activity.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 09 Sep 2024 13:43:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73688#M2833</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2024-09-09T13:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Quiz question Domain 2: Incident management</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73768#M2847</link>
      <description>Hi there, thanks for the clarification. I understand that assess and scoping damage is the role of the incident response team; I just thought they are also involved in reducing the impact of the incident by containing it.&lt;BR /&gt;&lt;BR /&gt;I guess the question is asking for the incident team's main responsibility, and assess/scoping is more of a key responsibility for them than reducing the impact? Why is that - is it because it's the most difficult part of incident response, or is it because containment is not done solely by the incident response team but also by the business?&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Sep 2024 11:12:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73768#M2847</guid>
      <dc:creator>Winny</dc:creator>
      <dc:date>2024-09-12T11:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Quiz question Domain 2: Incident management</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73773#M2848</link>
      <description>&lt;P&gt;Incident Management and Incident Response are roles that is included in various frameworks such as ITIL, NIST and so on. You can see more in&amp;nbsp;ISO/IEC 27035. I would point out that for the CISSP exam it is important to understand these roles and objectives. In here you can see that Incident Response is responsible for assessment and decision which would lead to scoping the work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Incident Response main responsibilities:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Planning and Preparation,&lt;BR /&gt;Detection and Reporting,&lt;BR /&gt;Assessment and Decision,&lt;BR /&gt;Response, and&lt;BR /&gt;Lessons Learned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Incident Management encompasses roles and functions for incident management, one of which is incident response. The focus of Incident Management assess the effectiveness of the Incidence Response team and make adjustments to the incident Response plans to become more effective to the organisation, thus reducing the impact of incidents to the business, not Incident Response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 13:00:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Clarification-on-Quiz-question-Domain-2-Incident-management/m-p/73773#M2848</guid>
      <dc:creator>funkychicken</dc:creator>
      <dc:date>2024-09-12T13:00:27Z</dc:date>
    </item>
  </channel>
</rss>

