CompTIA CySA+ (CS0-002) — Question 89
A company's legal department is concerned that its incident response plan does not cover the countless ways security incidents can occur. They have asked a security analyst to help tailor the response plan to provide broad coverage for many situations. Which of the following is the BEST way to achieve this goal?
Answer options
- A. Focus on incidents that have a high chance of reputation harm.
- B. Focus on common attack vectors first.
- C. Focus on incidents that affect critical systems.
- D. Focus on incidents that may require law enforcement support
Correct answer: B
Explanation
Focusing on common attack vectors first (option B) ensures that the response plan addresses the most likely threats, providing a foundation for broader coverage. Options A, C, and D, while important, are more specific and may not cover the wide range of potential incidents that could occur.