New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Lead-Cybersecurity-Manager Exam - Topic 5 Question 3 Discussion

Actual exam question for PECB's Lead-Cybersecurity-Manager exam
Question #: 3
Topic #: 5
[All Lead-Cybersecurity-Manager Questions]

Scenario 8: FindaxLabs is a financial institution that offers money transfers services globally The company Is known for quick money transfers at a low cost. To transfer money, users register with their email addresses and submit a photo of their ID card for identity verification. They also need to provide the recipient s bank account details alongside their own bank account details. Users can track the transfer through their accounts, either from the website or mobile app. As the company operates in a highly sensitive industry, it recognizes the importance of ensuring cybersecurity. As such, FindaxLabs has addressed its cybersecurity concerns through its business continuity plan.

Nevertheless, a few months ago, FindaxLabs detected suspicious activity on its network and realized that it was being attacked The attackers tried to gain access to customer information. Including emails, bank account numbers, and records of financial transactions. Upon receiving the alert, the incident response team responded swiftly Following the ICT readiness for business continuity (IRBC) policy and procedures, they immediately took down the communication channels to the server and went offline. Subsequently, they conducted vulnerability testing and network scanning, but did not identify any other backdoors. After dodging this attack, the company completely changed its approach toward cyber threats. Consequently, cybersecurity became one of their highest priorities.

FindaxLabs established a more comprehensive cybersecurity incident management plan based on its cybersecurity Incident management policy 10 effectively handle and mitigate future incidents and vulnerabilities. The cybersecurity incident management plan outlined a structured approach based on industry best practices and included various phases of the incident response process

The company also created a post-incident report to evaluate the effectiveness of their response capabilities and identify areas for improvement It documented all relevant information related to the incident, such as category, priority, status, and actions taken to resolve it Based on this documentation, it defined the IRBC activities that helped them respond to and recover from disruptions, creating an IRBC timeline. The timeline consisted of three main stages: incident detection, response, and recovery. The company evaluated whether IRBC objectives were met for each phase. Through this evaluation, they determined that improved collaboration between business managers and ICT staff, as well as the implementation of preventive measures such as antivirus and firewalls, would have provided layered protection and better integration of cybersecurity into the business continuity strategy.

Based on the scenario above, answer the following question:

Based on scenario 8, has FindaxLabs completed the "Do" phase of the Plan-Do-Check-Act cycle In IRBC?

Show Suggested Answer Hide Answer
Suggested Answer: A

Based on the scenario, FindaxLabs has completed the 'Do' phase of the Plan-Do-Check-Act (PDCA) cycle in IRBC. They implemented and operated the IRBC policy and procedures during the incident response, conducting actions such as taking down communication channels, performing vulnerability testing, and documenting the incident. This phase involves executing the planned actions to ensure ICT readiness and manage incidents effectively, as outlined in ISO/IEC 22301, which provides a framework for business continuity management systems, including the implementation and operation of continuity procedures.


Contribute your Thoughts:

0/2000 characters
Kristofer
3 months ago
Wait, they went offline completely? That’s surprising!
upvoted 0 times
...
Vernice
3 months ago
Sounds like they’re on the right track with cybersecurity now.
upvoted 0 times
...
Linsey
3 months ago
But did they really fix all the vulnerabilities?
upvoted 0 times
...
Levi
4 months ago
I agree, they took action quickly!
upvoted 0 times
...
Almeta
4 months ago
They definitely implemented the IRBC policies after the attack.
upvoted 0 times
...
Sharee
4 months ago
I remember that in our study sessions, we talked about how implementation is key. If they only established the policies, then they haven't completed the "Do" phase.
upvoted 0 times
...
Colette
4 months ago
This reminds me of a practice question where we discussed the importance of assessing policies. Maybe they did assess them after the incident?
upvoted 0 times
...
Providencia
4 months ago
I'm not entirely sure, but it seems like they just established the policies and didn't fully implement them yet.
upvoted 0 times
...
Virgilio
5 months ago
I think they might have completed the "Do" phase since they implemented the IRBC policy after the attack.
upvoted 0 times
...
Julianna
5 months ago
I'm pretty confident the answer is A. The scenario states that FindaxLabs "immediately took down the communication channels to the server and went offline" in response to the incident, which clearly shows they implemented their IRBC policy and procedures. The additional steps they took, like evaluating their response, are part of the "Check" phase, not the "Do" phase.
upvoted 0 times
...
Valentine
5 months ago
I think the answer is A. The scenario clearly states that FindaxLabs "immediately took down the communication channels to the server and went offline" in response to the incident, which indicates they implemented their IRBC policy and procedures. The fact that they also evaluated their response afterwards doesn't change the fact that they completed the "Do" phase.
upvoted 0 times
...
Precious
5 months ago
Hmm, I'm a bit confused here. The question is asking about the "Do" phase, but the scenario mentions that they also evaluated the effectiveness of their response and identified areas for improvement. Doesn't that suggest they've completed the "Check" phase as well? I'm not sure if option A is the best answer.
upvoted 0 times
...
Dorsey
5 months ago
This scenario seems pretty straightforward. The key is to focus on the "Do" phase of the Plan-Do-Check-Act cycle. Based on the details provided, it looks like FindaxLabs has implemented and operated their IRBC policy and procedures, so I'd go with option A.
upvoted 0 times
...
Miles
5 months ago
I'm leaning towards option B. The scenario mentions that FindaxLabs "created a post-incident report to evaluate the effectiveness of their response capabilities and identify areas for improvement." This suggests they've not only implemented their IRBC policy, but also assessed the results and reported them to management, which would be the "Check" phase.
upvoted 0 times
...
Ronald
5 months ago
I think I know this one - SAP BTP supports the Cloud Foundry environment, the ABAP environment, and the Kyma runtime, so I'll go with option A.
upvoted 0 times
...
Reid
5 months ago
Verbal majority acceptance by a committee doesn't seem as strong as a written record. I'll probably go with the memo option for this one.
upvoted 0 times
...
Elli
1 year ago
I don't think so, the scenario only mentions that they have established and implemented the policies.
upvoted 0 times
...
Jesusita
1 year ago
Well, this scenario is more complex than finding my car keys. I'm going to go with A, but I'm keeping an eye out for any hidden 'socks' in the details.
upvoted 0 times
Chanel
1 year ago
I agree, option A seems like the right choice based on the scenario.
upvoted 0 times
...
Salome
1 year ago
Yeah, they have implemented and operated the IRBC policy and procedures.
upvoted 0 times
...
Brice
1 year ago
I think FindaxLabs has completed the 'Do' phase of the Plan-Do-Check-Act cycle.
upvoted 0 times
...
...
Felix
1 year ago
But do you think they have assessed the IRBC policies and reported the results to management?
upvoted 0 times
...
Wilbert
1 year ago
Ha! 'FindaxLabs' - sounds like a lab that specializes in finding lost socks. Anyway, I reckon B is the right answer. They've assessed the IRBC policies and reported the results, but the 'Do' phase is still a work in progress.
upvoted 0 times
...
Edna
1 year ago
I agree with Elli, they have implemented and operated the IRBC policy and procedures.
upvoted 0 times
...
Whitley
1 year ago
Hmm, I'm not so sure. The scenario mentions they established a more comprehensive cybersecurity incident management plan, but it doesn't explicitly say they've implemented it. I'm going with C.
upvoted 0 times
Leandro
1 year ago
Definitely, it's always better to prioritize security measures to protect sensitive information.
upvoted 0 times
...
Nelida
1 year ago
Yeah, it's better to be cautious in this situation. Cybersecurity is crucial.
upvoted 0 times
...
Elinore
1 year ago
I agree with you. It seems like they have the plan in place but may not have fully put it into action yet.
upvoted 0 times
...
Frederica
1 year ago
I think they have only established the IRBC policy and procedures, but not implemented them. So, I'll go with C.
upvoted 0 times
...
...
Elli
1 year ago
I think FindaxLabs has completed the 'Do' phase of the Plan-Do-Check-Act cycle.
upvoted 0 times
...
Tiera
1 year ago
I think the correct answer is A. The scenario clearly states that the incident response team responded swiftly and followed the IRBC policy and procedures, indicating that the 'Do' phase has been completed.
upvoted 0 times
Marshall
1 year ago
I agree with you. The incident response team did take immediate action.
upvoted 0 times
...
Ozell
1 year ago
A) Yes, the IRBC policy and procedures are implemented and operated
upvoted 0 times
...
William
1 year ago
Yes, the 'Do' phase of the Plan-Do-Check-Act cycle in IRBC has been completed.
upvoted 0 times
...
Bettina
1 year ago
I agree, the incident response team did act swiftly and followed the IRBC policy and procedures.
upvoted 0 times
...
...

Save Cancel