CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 36


Which of the following is the BEST indicator of the effectiveness of an organization's incident response program?

Show Answer
Correct Answer: BD

The financial impact per security event is the best indicator of the effectiveness of an organization's incident response program. This metric provides a direct measurement of how well the incident response program reduces the cost and damages associated with security events. If the financial impact is low, it suggests that the incident response program is effectively identifying, containing, and mitigating security incidents to minimize their overall impact on the organization.

Discussion

17 comments
Sign in to comment
Victor83516Option: B
Sep 6, 2022

How to ensure the effectiveness of incident response? Incident response is on the one hand whether you are aware of the occurrence of an incident, and on the other hand, how quickly you can react after the incident is discovered to reduce the impact. B is more reasonable than D, because in principle most applications will be included in the protection, but there are always a few applications in the organization that have not been included in the protection scope, but the percentage of protection is increased through incident response. The financial impact of each security incident is not necessarily the same, nor necessarily proportional to the length of the incident response time, so I think B would be the more appropriate answer.

Wakazdave
Sep 15, 2022

But then being protected doe not guarantee that the protection is effective

babadook13Option: D
Sep 19, 2022

D is the answer

Forever25Option: D
Oct 14, 2022

D should be the correct answer

swmasindeOption: D
Feb 18, 2023

D is the answer, check CISA Q&A A5-246

Baggio13
Oct 31, 2023

security event is not a security incident so B is the answer and double-check A5-246 as well

[Removed]Option: C
Nov 24, 2023

per CRM incidents occur because vulnerabilities are not addresses properly. As such, an effective incident management program should have all security vulnerabilties patched which meets the initial goal to avoid future reoccurrence of such incident.

[Removed]
Nov 24, 2023

incidents can aride due to vulnerbilities in non-applications and financial impact is not an appropriate measurement as it can vary between incidents

mohamedadel2024Option: D
Apr 15, 2024

D as per the CISA Q&A Ch#5

analuisamoreiraOption: D
Jun 20, 2024

D, financial impact is a much more critical information than Percentage of applications. It is about priorities

007GeorgeoOption: D
May 1, 2023

I agree D should be the answer

StephenFOHAOption: B
May 28, 2023

B is correct

i91290Option: D
Jun 20, 2023

D is the right answer

Baggio13
Oct 31, 2023

security event is not a security incident so B is the answer

sheetalj845Option: D
Aug 19, 2023

D is the right answer

Baggio13
Oct 31, 2023

security event is not a security incident so B is the answer

[Removed]
Aug 20, 2023

CISA, CISM, CRISC, CGEIT, CompTIA, CCNA, PMP, PMI-RMP, PMI-ACP, PMI-PBA, PMI-CAPM, SCRUM, Azure, AWS, Salesforce, ITIL, ISTQB, CLOUD, CEHv12, CCISO, GMAT, Six-sigma, SAP, Oracle, ISO... Get Certified with 100% pass guarantee. PAYMENT ONLY AFTER PASSING Contact : +1(940) 268-5570‬ https://wa.me/message/UFCQOHSDPAM3C1

Baggio13Option: B
Oct 31, 2023

security event is not a security incident so B is the answer

sundersam23
Feb 1, 2024

Why would there be financial impact for security events?

echo_certOption: B
Feb 22, 2024

B - D was included to mislead

fori12Option: D
Apr 4, 2024

The most important indicator is the financial impact per security incident. It may not be possible to prevent incidents entirely, but the team should be able to limit the cost of incidents through a combination of effective prevention, detection and response.

5b56aaeOption: D
Apr 15, 2024

looking for reponse indicators

a84nOption: D
Apr 25, 2024

Answer: D