Security Operations Question #31

Your security team detected suspicious activity suggesting a possible insider threat in finance. What should be the FIRST step in the incident response process?

A. Assemble a team to gather publicly available information (OSINT) to help verify and expand on the detected threat.
B. Schedule a discussion with the Human Resources department to evaluate potential disciplinary actions.
C. Launch a formal investigation to gather evidence and assess the extent of the threat.
D. Initiate an internal audit of all finance-related activities and access logs to identify anomalies
Domain Concept: Security Operations

This scenario evaluates management-level decision making in Security Operations. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top