200-201 Question 315
Single answerA cybersecurity analyst at your organization has identified an incident involving unauthorized access to sensitive customer data. While responding to the incident, the analyst realizes that no documented procedures exist for handling this type of breach. Which action should the organization prioritize to improve its incident response process?
- A
Develop and implement a comprehensive incident response plan.
- B
Train employees to recognize phishing emails.
- C
Invest in an advanced intrusion detection system (IDS).
- D
Conduct a tabletop exercise with the existing IT team.
Show answer and explanation
Correct answer: A
Explanation
The absence of a documented incident response plan highlights a gap in the organization's security policies and procedures. Developing and implementing such a plan ensures that the organization has a structured approach to managing cybersecurity incidents, which is critical for minimizing damage and ensuring compliance with security standards.
- A. Correct.
Developing and implementing a comprehensive incident response plan addresses the root issue: the absence of documented procedures for handling breaches. This ensures that future incidents are managed systematically.
- B. Incorrect.
Training employees to recognize phishing emails is important for overall security awareness but does not address the specific issue of responding to breaches.
- C. Incorrect.
Investing in an advanced IDS improves detection capabilities but does not resolve the lack of documented procedures for incident response.
- D. Incorrect.
Conducting a tabletop exercise is a valuable activity but requires the existence of documented procedures to simulate and test effectively.