SY0-701 Question 388
Single answerTesting: Tabletop exercise , SimulationA healthcare company wants to evaluate its incident response plan for a ransomware attack without disrupting production systems or risking patient data. The CISO asks the security team to run an exercise in which department leads walk through how they would communicate, escalate, and make decisions during a simulated attack timeline. No live malware, production changes, or hands-on technical actions will occur. Which type of test best meets this requirement?
- A
Tabletop exercise
- B
Simulation test
- C
Vulnerability scan
- D
Penetration test
Show answer and explanation
Correct answer: A
Explanation
The best answer is a tabletop exercise because the organization wants to validate incident response procedures, communication paths, and decision-making in a low-risk way. In Security+ terms, tabletop exercises are discussion-based and commonly used to test plans such as incident response, business continuity, and disaster recovery. By contrast, simulations are more interactive and operational, often involving a realistic enactment of the scenario rather than just a facilitated discussion. Industry best practices, including guidance from NIST such as NIST SP 800-61 for incident handling and NIST SP 800-84 for test, training, and exercise programs, support using tabletop exercises to assess readiness, clarify roles, and identify procedural gaps without affecting production environments.
- A. Correct.
Correct. A tabletop exercise is a discussion-based review of roles, decisions, communications, and procedures during a hypothetical scenario. It is specifically designed to validate plans and coordination without making changes to production systems or executing live attack activity. This matches the requirement for leaders to talk through escalation and response steps during a ransomware scenario.
- B. Incorrect.
Incorrect. A simulation test is more operational and attempts to imitate an incident more realistically, often involving technical teams, tools, and procedural execution. While still controlled, it is more hands-on than a discussion-based walkthrough. The scenario explicitly states that no live technical actions or production changes will occur, making tabletop the better fit.
- C. Incorrect.
Incorrect. A vulnerability scan identifies known weaknesses in systems and applications. It does not primarily test incident response decision-making, executive communications, or coordination among department leaders during a ransomware event.
- D. Incorrect.
Incorrect. A penetration test is designed to exploit vulnerabilities to demonstrate impact and security weaknesses. Although it can inform preparedness, it is not the best choice for validating communication and decision processes in a no-impact, discussion-only exercise.