New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27035-Lead-Incident-Manager Exam - Topic 6 Question 2 Discussion

Actual exam question for PECB's ISO-IEC-27035-Lead-Incident-Manager exam
Question #: 2
Topic #: 6
[All ISO-IEC-27035-Lead-Incident-Manager Questions]

Scenario 1: RoLawyers is a prominent legal firm based in Guadalajara, Mexico. It specializes in a wide range of legal services tailored to meet the diverse needs of its clients. Committed to excellence and integrity, RoLawyers has a reputation for providing legal representation and consultancy to individuals, businesses, and organizations across various sectors.

Recognizing the critical importance of information security in today's digital landscape, RoLawyers has embarked on a journey to enhance its information security measures. This company is implementing an information security incident management system aligned with ISO/IEC 27035-1 and ISO/IEC 27035-2 guidelines. This initiative aims to strengthen RoLawyers' protections against possible cyber threats by implementing a structured incident response process to provide guidance on establishing and maintaining a competent incident response team.

After transitioning its database from physical to online infrastructure to facilitate seamless information sharing among its branches, RoLawyers encountered a significant security incident. A malicious attack targeted the online database, overloading it with traffic and causing a system crash, making it impossible for employees to access it for several hours.

In response to this critical incident, RoLawyers quickly implemented new measures to mitigate the risk of future occurrences. These measures included the deployment of a robust intrusion detection system (IDS) designed to proactively identify and alert the IT security team of potential intrusions or suspicious activities across the network infrastructure. This approach empowers RoLawyers to respond quickly to security threats, minimizing the impact on their operations and ensuring the continuity of its legal services.

By being proactive about information security and incident management, RoLawyers shows its dedication to protecting sensitive data, keeping client information confidential, and earning the trust of its stakeholders. Using the latest practices and technologies, RoLawyers stays ahead in legal innovation and is ready to handle cybersecurity threats with resilience and careful attention.

According to scenario 1, RoLawyers incorporated a structured incident management process to provide guidance on establishing and maintaining a competent incident response team. Is this acceptable?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Eloisa
10 hours ago
A structured approach is essential for a competent response team!
upvoted 0 times
...
Ines
6 days ago
Wait, did they really have a major attack? That's surprising!
upvoted 0 times
...
Franchesca
11 days ago
Definitely agree, consistency is key in incident management!
upvoted 0 times
...
Wynell
16 days ago
Really? I think they should focus more on prevention.
upvoted 0 times
...
Evan
21 days ago
Sounds like a solid plan for handling incidents!
upvoted 0 times
...
Howard
26 days ago
Haha, I bet the IT team at RoLawyers is on high alert after that database crash. Time to bring out the big cybersecurity guns!
upvoted 0 times
...
Deangelo
1 month ago
The IDS deployment is a smart move to proactively detect and alert the team about potential threats. Gotta stay one step ahead of those hackers!
upvoted 0 times
...
Myrtie
1 month ago
C) I agree, the structured approach is important for consistency in incident handling, not just for the incident response team.
upvoted 0 times
...
Lemuel
1 month ago
A) Absolutely, a structured incident management process is crucial for effective incident response. It helps the company be prepared and respond quickly to security threats.
upvoted 0 times
...
Terina
2 months ago
I remember a practice question that discussed the importance of consistency in incident handling, so option C might be right. It’s not just about having a response team but ensuring everyone follows the same process.
upvoted 0 times
...
Gerald
2 months ago
I'm not entirely sure, but I feel like option B could be valid too. It seems like focusing on prevention is just as important as having a response plan.
upvoted 0 times
...
Janessa
2 months ago
Okay, let me think this through. The question is asking if the structured incident management process is acceptable, and the options seem to be focused on the purpose of that process. I'm leaning towards option C, as it suggests the process is about ensuring consistency in incident handling across the organization, rather than just guidance for the response team.
upvoted 0 times
...
Leslie
2 months ago
I feel pretty confident about this one. The scenario states that RoLawyers implemented the incident management system to strengthen its protections against cyber threats and provide guidance on establishing an incident response team. So option A seems like the correct answer, as the structured process is meant to support their incident response capabilities.
upvoted 0 times
...
Ivan
2 months ago
I think option A makes sense because having a structured incident management process is crucial for effectively addressing incidents when they happen.
upvoted 0 times
...
Brynn
3 months ago
I’m a bit confused about this one. I thought a structured approach was necessary for both response and prevention, but I can see how the emphasis might differ in each option.
upvoted 0 times
...
Sharmaine
3 months ago
Hmm, I'm a bit confused by this question. The scenario mentions that RoLawyers implemented a structured incident management process, but it's not clear to me if that's the only focus or if it's part of a broader approach. I'll need to re-read the details carefully to decide which option best fits.
upvoted 0 times
...
Tammi
3 months ago
This seems like a straightforward question about incident response management. I think the key is understanding the purpose of the structured incident management process that RoLawyers implemented. The scenario indicates it was to provide guidance on establishing and maintaining a competent incident response team, so I'd go with option A.
upvoted 0 times
Bettina
2 months ago
But isn't it also important to focus on prevention?
upvoted 0 times
...
Ilda
3 months ago
I agree with you, option A makes the most sense.
upvoted 0 times
...
...

Save Cancel