SY0-701 exam dumps

SY0-701 practice question 389 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 389

Single answerTesting: Tabletop exercise , Simulation

A security manager wants to validate the company incident response plan for a ransomware attack without risking disruption to production systems. The goal is to have executives, legal, IT, and communications staff walk through decisions such as containment, public messaging, and recovery sequencing. Which testing approach would BEST meet this goal?

  1. A

    Conduct a tabletop exercise using a facilitated ransomware scenario discussion

  2. B

    Run a full simulation that encrypts selected production endpoints to measure response time

  3. C

    Perform a vulnerability scan against file servers during business hours

  4. D

    Launch a red-team engagement to gain initial access and trigger real incident handling

Show answer and explanation

Correct answer: A

Explanation

The best answer is a tabletop exercise because the scenario emphasizes validating the incident response plan through coordinated discussion among technical and nontechnical stakeholders, while avoiding impact to production. In security practice, tabletop exercises are commonly used to review playbooks, escalation procedures, legal/regulatory obligations, executive decision points, and external/internal communications. By contrast, simulations are more hands-on and can emulate real events with greater realism, making them useful when an organization wants to test operational execution rather than primarily discussion and planning. This aligns with common incident response guidance from sources such as NIST SP 800-61, which highlights the importance of exercising incident response capabilities, including plan reviews and scenario-based practice, to improve preparedness.

  • A. Correct.

    Correct. A tabletop exercise is a discussion-based test in which stakeholders review roles, responsibilities, decisions, and communication paths for a realistic scenario. It is specifically well suited for validating incident response procedures, escalation paths, and coordination among business and technical teams without affecting live systems. This matches the requirement to test the plan safely and include executives, legal, IT, and communications staff.

  • B. Incorrect.

    Incorrect. A simulation is more operationally involved and is designed to imitate real conditions more closely than a tabletop exercise. Encrypting production endpoints would introduce unnecessary operational risk and does not align with the stated requirement to avoid disruption. While simulations can be valuable, this option is too invasive for the objective.

  • C. Incorrect.

    Incorrect. A vulnerability scan identifies technical weaknesses but does not validate cross-functional decision-making, communications, legal considerations, or recovery prioritization during an incident. Someone might choose this because scans are common security tests, but they do not test the incident response process in the way described.

  • D. Incorrect.

    Incorrect. A red-team engagement can test detection and response capabilities in a realistic manner, but it is not the best fit here because the goal is a low-risk, discussion-based validation involving multiple business stakeholders. A red-team exercise is more adversarial, technical, and potentially disruptive than needed for this objective.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam