Exam CISA All QuestionsBrowse all questions from this exam
Question 36

Which of the following is the BEST indicator of the effectiveness of an organization's incident response program?

    Correct Answer: D

    The financial impact per security event is the best indicator of the effectiveness of an organization's incident response program. This metric provides a direct measurement of how well the incident response program reduces the cost and damages associated with security events. If the financial impact is low, it suggests that the incident response program is effectively identifying, containing, and mitigating security incidents to minimize their overall impact on the organization.

Discussion
Victor83516Option: B

How to ensure the effectiveness of incident response? Incident response is on the one hand whether you are aware of the occurrence of an incident, and on the other hand, how quickly you can react after the incident is discovered to reduce the impact. B is more reasonable than D, because in principle most applications will be included in the protection, but there are always a few applications in the organization that have not been included in the protection scope, but the percentage of protection is increased through incident response. The financial impact of each security incident is not necessarily the same, nor necessarily proportional to the length of the incident response time, so I think B would be the more appropriate answer.

Wakazdave

But then being protected doe not guarantee that the protection is effective

analuisamoreiraOption: D

D, financial impact is a much more critical information than Percentage of applications. It is about priorities

mohamedadel2024Option: D

D as per the CISA Q&A Ch#5

[Removed]Option: C

per CRM incidents occur because vulnerabilities are not addresses properly. As such, an effective incident management program should have all security vulnerabilties patched which meets the initial goal to avoid future reoccurrence of such incident.

[Removed]

incidents can aride due to vulnerbilities in non-applications and financial impact is not an appropriate measurement as it can vary between incidents

swmasindeOption: D

D is the answer, check CISA Q&A A5-246

Baggio13

security event is not a security incident so B is the answer and double-check A5-246 as well

Forever25Option: D

D should be the correct answer

babadook13Option: D

D is the answer

a84nOption: D

Answer: D

5b56aaeOption: D

looking for reponse indicators

fori12Option: D

The most important indicator is the financial impact per security incident. It may not be possible to prevent incidents entirely, but the team should be able to limit the cost of incidents through a combination of effective prevention, detection and response.

echo_certOption: B

B - D was included to mislead

Baggio13Option: B

security event is not a security incident so B is the answer

sundersam23

Why would there be financial impact for security events?

[Removed]

CISA, CISM, CRISC, CGEIT, CompTIA, CCNA, PMP, PMI-RMP, PMI-ACP, PMI-PBA, PMI-CAPM, SCRUM, Azure, AWS, Salesforce, ITIL, ISTQB, CLOUD, CEHv12, CCISO, GMAT, Six-sigma, SAP, Oracle, ISO... Get Certified with 100% pass guarantee. PAYMENT ONLY AFTER PASSING Contact : +1(940) 268-5570‬ https://wa.me/message/UFCQOHSDPAM3C1

sheetalj845Option: D

D is the right answer

Baggio13

security event is not a security incident so B is the answer

i91290Option: D

D is the right answer

Baggio13

security event is not a security incident so B is the answer

StephenFOHAOption: B

B is correct

007GeorgeoOption: D

I agree D should be the answer