🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 7 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your security operations team is updating its incident response plan for a multi-account AWS environment. To comply with the NIST SP 800-61 preparation phase guidance on ensuring tool and resource readiness, which of the following actions will MOST improve the team's ability to collect and analyze evidence quickly when a security incident is declared?

  • Enable a cross-account AWS CloudTrail trail that logs all management events to an immutable Amazon S3 bucket with Object Lock enabled.

  • Publish an incident severity matrix in the organization's wiki that maps attack categories to notification requirements and on-call contacts.

  • Conduct quarterly tabletop exercises that rehearse the incident escalation workflow with senior management and legal counsel.

  • Create and maintain a hardened Amazon Machine Image (AMI) that contains preconfigured forensic and malware analysis tools, and allow deployment only in a dedicated, isolated investigation account.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot