Certified Information Security Manager (CISM) — Question 231
Which of the following is the MOST beneficial outcome of testing an incident response plan?
Answer options
- A. The response includes escalation to senior management.
- B. Test plan results are documented.
- C. Incident response time is improved.
- D. The plan is enhanced to reflect the findings of the test.
Correct answer: D
Explanation
The correct answer is D, as the enhancement of the plan based on test findings ensures continuous improvement and effectiveness in future incidents. Options A, B, and C, while beneficial, do not directly contribute to the evolution of the incident response strategy as significantly as option D does.