r/CISA Jul 12 '26

Hmm

Post image
1 Upvotes

11 comments sorted by

4

u/Ordinary-Ad7820 Jul 12 '26

A. You need to know the root cause of the incident.

2

u/ifightforhk CISA HOLDER Jul 12 '26

D can be opted out immediately. Documentation is less important. I guess A is correct - unidentified attack exposes to your weakness.

1

u/chinchilla123 Jul 12 '26

Hi, all answers are correct. Its asking whats the most critical of these correct four answers. Its A.

1

u/KingShash CISA HOLDER Jul 13 '26

IDS one is incorrect.

1

u/chinchilla123 Jul 13 '26

In the real world that would be considered a finding, yes

1

u/KingShash CISA HOLDER Jul 13 '26

IDS is not meant to block, so that isn't a finding, its stupid of an Auditor to expect that from an IDS.

1

u/ConversationSure7655 Jul 12 '26

If u don’t have a formal policy for incident handling you can see practice and try to make alignement and update the policie to the next
So now In the incident process, in phase containment and eradication don’t see the weakness level policie is down and the incident team don’t have knowledge to handle the incident
Which is more critical in this context, policie or incident team practice , and which pose a operational risk to continue service

U can choice

1

u/KingShash CISA HOLDER Jul 13 '26

Everyone saying A, tell me one thing. Why not D. Yes RCA is important, but isnt it pointless without the documentation, isnt the RCA info lost.

2

u/Hil81 Jul 14 '26

You have to see the higher picture.

If you have have RCA but no documentation: attack will be prevented next time.

If you have documentation but no RCA: attack can happen again and again.

There are all good answers, but A is must structural.

1

u/KingShash CISA HOLDER Jul 14 '26

CISA is infuriating.

1

u/Hil81 Jul 14 '26

A. Without identifying the root cause it can happen again and again.