Courseiva
Security OperationsmediumMultiple SelectObjective-mapped

CISSP Security Operations Practice Question

A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Forensic Investigator

Standard IR team roles include IR manager, security analyst, forensic investigator, communications lead, and legal counsel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Forensic Investigator

    Why this is correct

    A forensic investigator is crucial for preserving the chain of custody, analyzing digital artifacts, and determining the root cause and scope of an incident. Their specialized skills ensure that evidence is admissible in legal proceedings and that a thorough post-incident analysis can be conducted to prevent future occurrences. This role is typically part of a Tier 2 or Tier 3 response, providing deep technical insight.

  • Human Resources Representative

    Why it's wrong here

    While Human Resources may be consulted for personnel-related issues arising from an incident, such as employee misconduct or notification requirements, they are not a primary, core member of the technical incident response team. Their involvement is typically peripheral and reactive to the incident's impact on staff, rather than directly contributing to the technical containment, eradication, or recovery efforts.

  • Incident Response Manager

    Why this is correct

    The Incident Response Manager is a critical leadership role responsible for overseeing the entire incident lifecycle, from detection to post-incident review. This individual coordinates resources, communicates status updates to stakeholders, makes strategic decisions regarding containment and eradication, and ensures adherence to established incident response plans and policies. They are essential for effective incident management and strategic direction.

  • Chief Financial Officer

    Why it's wrong here

    The Chief Financial Officer (CFO) is responsible for managing an organization's financial actions and is not a direct participant in the operational incident response team. While a major incident might have significant financial implications requiring the CFO's awareness or approval for budget allocation, their role is strategic and executive, not hands-on in the technical or tactical aspects of incident handling or recovery.

  • Communications Lead

    Why this is correct

    A Communications Lead is vital for managing all internal and external messaging during an incident, ensuring consistent, accurate, and timely information dissemination. This role crafts statements for media, customers, employees, and regulatory bodies, helping to manage reputational risk and maintain stakeholder trust. Effective communication is a cornerstone of a well-executed incident response plan, mitigating broader organizational impact.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.