CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 1323


Which of the following is the MOST important consideration when designing a risk-based incident response management program?

Show Answer
Correct Answer:

Discussion

3 comments
Sign in to comment
blehblehOption: B
Oct 20, 2024

This is B. We are trying to minimize false positives and false negatives to find the real risk and focus on it.

CCNPWILL
May 2, 2025

what does that have to do with "designing a risk-based incident response management program?"

Enig
Nov 12, 2024

B. Minimizing false-positive and false-negative alerts In a risk-based incident response management program, minimizing false positives and false negatives is crucial. False positives can lead to wasted resources on non-critical events, while false negatives can result in missing actual threats, increasing risk to the organization. Effective incident response relies on accurate detection, so reducing these errors is essential to ensure that the program can promptly identify and respond to legitimate incidents. While monitoring low-risk events, testing the plan, and assigning roles are important, they are secondary to ensuring accurate alerting for risk-based prioritization.

CCNPWILL
May 2, 2025

I can see this angle also. this would make sense. Agreed with bleh and Enig. the overall efficiency of the plan is founded on legit alerts.

CCNPWILLOption: B
May 2, 2025

B. Voting against the examtopics mods.