Which describes a Reactive Organization approach?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

Which describes a Reactive Organization approach?

Explanation:
Reactive organizations initiate incident response when an external signal arrives or a notification is received. The statement that the incident starts when notification comes in captures this idea directly: the process is triggered by an inbound alert or report, not by proactive hunting or pre-emptive monitoring. A call from a government agency, while an external notification, is just one instance and doesn’t define the general approach. Threat information from vendors or security appliance alerts describe sources of signals but don’t specify how the organization typically begins response as a posture. The essence of a reactive model is mobilizing once something is reported or alerted, which this option expresses most clearly.

Reactive organizations initiate incident response when an external signal arrives or a notification is received. The statement that the incident starts when notification comes in captures this idea directly: the process is triggered by an inbound alert or report, not by proactive hunting or pre-emptive monitoring.

A call from a government agency, while an external notification, is just one instance and doesn’t define the general approach. Threat information from vendors or security appliance alerts describe sources of signals but don’t specify how the organization typically begins response as a posture. The essence of a reactive model is mobilizing once something is reported or alerted, which this option expresses most clearly.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy