Courseiva

GSEC Security Frameworks and CIS Controls Practice Question

A multinational corporation is aligning its incident response program with the CIS Critical Security Controls. They are focusing on CIS Control 17: Incident Response Management. Which of the following activities best demonstrates the establishment of a formal incident response process as required by this control?

⚠ Common exam trap

The trap here is focusing on tools or exercises as the primary requirement, while overlooking the need for a documented incident response plan that defines roles and communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures.

CIS Control 17 requires establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures. This formal documentation is the foundation of the incident response process. While tools, exercises, and designated personnel are valuable, they are not sufficient without a documented plan that guides the overall response effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures.

    Why this is correct

    Safeguard 17.1 explicitly requires establishing and maintaining a documented incident response plan. This plan must define roles, responsibilities, and communication procedures. It is the cornerstone of CIS Control 17. A documented plan ensures that all stakeholders know their duties during an incident, facilitating a coordinated and effective response. This is the best demonstration of a formal process.

  • ✗

    Designating a single individual as the incident response coordinator without a formal team.

    Why it's wrong here

    CIS Control 17 requires establishing an incident response process that includes defining roles and responsibilities. Designating a single individual without a formal team and documented process does not meet the requirement. The control emphasizes a structured approach with clear escalation paths and team coordination. A lone coordinator lacks the necessary structure and support.

  • ✗

    Conducting an annual tabletop exercise without updating the incident response plan based on findings.

    Why it's wrong here

    Tabletop exercises are important, but they must be part of a continuous improvement cycle. CIS Control 17 requires that the incident response plan be updated based on lessons learned from exercises and actual incidents. Conducting an exercise without updating the plan misses the opportunity to improve and does not fully satisfy the control's requirements for maintaining an effective process.

  • ✗

    Purchasing an incident response automation tool to streamline handling of security incidents.

    Why it's wrong here

    While automation can enhance incident response, it is not the foundational requirement. CIS Control 17 first requires establishing a documented incident response process, including roles, responsibilities, and communication plans. Tools support the process but do not replace the need for a formalized plan. Without a defined process, automation may be misdirected or ineffective.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.