N10-009 Question 224
Single answerTesting: Tabletop exercises, Validation testsA network administrator is helping prepare the company for a disaster recovery audit. Management wants to verify that the incident response team understands its roles during a ransomware event, but they do not want to disrupt production systems. They also want a separate activity later to confirm that backup restoration and failover procedures actually work as documented. Which testing approach should the administrator recommend FIRST to meet the immediate requirement?
- A
Conduct a tabletop exercise in which stakeholders walk through the ransomware scenario and discuss decisions, communication paths, and responsibilities
- B
Run a validation test by failing over production services to the disaster recovery site during business hours
- C
Perform a vulnerability scan against the backup servers to confirm the incident response plan is effective
- D
Review the network diagram and asset inventory without involving the incident response team
Show answer and explanation
Correct answer: A
Explanation
The best first step is a tabletop exercise because it is specifically designed to evaluate people, processes, and communications in a low-risk, discussion-based format. In real-world incident response and disaster recovery planning, tabletop exercises are commonly used before more technical testing because they expose gaps in roles, escalation procedures, and decision-making without impacting live services. A separate validation test is then appropriate to confirm that technical recovery controls, such as backup restoration, service failover, and documented recovery steps, actually work as intended. This aligns with common business continuity and disaster recovery best practices, including phased testing approaches recommended by standards and guidance such as NIST contingency planning and incident response documentation, where organizations first validate procedures and responsibilities, then verify technical recovery capabilities through controlled testing.
- A. Correct.
Correct. A tabletop exercise is a discussion-based test used to validate that participants understand roles, escalation paths, communications, and decision-making during an incident, without making changes to production systems. This directly matches the requirement to verify team readiness for a ransomware scenario while avoiding operational disruption.
- B. Incorrect.
Incorrect. A validation test is appropriate for later confirmation that documented recovery procedures actually function, such as restoring backups or testing failover. However, failing over production services during business hours would be unnecessarily disruptive for the stated immediate goal, which is to assess team understanding without affecting production.
- C. Incorrect.
Incorrect. A vulnerability scan can identify security weaknesses on systems, but it does not test whether the incident response team understands its roles or whether the response process will be followed correctly during a ransomware event. This distractor reflects the misconception that security scanning is interchangeable with operational readiness testing.
- D. Incorrect.
Incorrect. Reviewing documentation such as network diagrams and asset inventories can support planning, but by itself it does not test how the incident response team will coordinate, communicate, or make decisions under a simulated incident. The key missing element is active participation by stakeholders.