Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?
An incident response playbook delivers the step-by-step technical instructions the stem demands, mapping specific containment, eradication and recovery actions to a defined incident type. Unlike broader plans or procedures, it prescribes exact commands and decision points, so responders execute consistent, repeatable actions under pressure.
Why this answer
C is correct because an incident response playbook provides detailed, step-by-step technical instructions for handling a specific type of security incident (e.g., ransomware, DDoS, phishing). Unlike the higher-level incident response plan, a playbook contains precise technical actions, such as commands to isolate a host, indicators of compromise (IOCs) to block, and escalation criteria tailored to a particular threat.
Exam trap
The trap here is that candidates confuse the incident response plan (strategic, high-level) with the playbook (tactical, incident-specific), often selecting the plan because it sounds like the most comprehensive document, but the question explicitly asks for 'step-by-step technical instructions' which only the playbook provides.
How to eliminate wrong answers
Option A is wrong because the incident response plan is a strategic document that outlines the overall process, roles, and coordination for incident management, not the granular technical steps for a specific incident type. Option B is wrong because the incident response policy defines high-level management intent, compliance requirements, and governance, not operational technical procedures. Option D is wrong because communication templates provide pre-formatted messages for notifying stakeholders (e.g., legal, PR, customers) but do not contain the technical steps needed to contain, eradicate, or recover from a security incident.