QuestionQ398

Incident Management

An information security team has verified that threat actors are exploiting a newly disclosed critical vulnerability in an application. Which of the following should be performed FIRST?

  • A Notify senior management.
  • B Prevent access to the application.
  • C Invoke the incident response plan.
  • D Install additional application controls.
Explanation

Confirmed exploitation of a critical application vulnerability constitutes a security incident. Invoking the incident response plan activates the approved process for assessment, containment, communications, escalation, eradication, and recovery.

Community Discussion

No comments yet. Be the first to start the discussion!