easyMultiple ChoiceObjective-mapped
CISSP Practice Question: Is a primary purpose of conducting a tabletop…
Which of the following is a primary purpose of conducting a tabletop exercise for incident response?
⚠ Common exam trap
Many candidates confuse a tabletop exercise with a technical drill or live-fire exercise, mistakenly thinking it tests tool capabilities or system-level actions, when in fact it strictly evaluates human processes and communication workflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate communication and decision-making processes.
A tabletop exercise is a discussion-based session where participants walk through a simulated incident scenario to evaluate the effectiveness of communication channels, decision-making hierarchies, and coordination among stakeholders. It does not involve live systems or technical testing, so its primary purpose is to validate the procedural and human elements of the incident response plan, such as who notifies whom and how escalation decisions are made.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Measure the effectiveness of backup restoration.
Why it's wrong here
Measuring the effectiveness of backup restoration involves actual execution of recovery procedures, verifying data integrity, and timing the recovery process against established Recovery Time Objectives (RTOs). Tabletop exercises, being discussion-based simulations, do not involve the physical activation or testing of backup systems. Therefore, they cannot provide empirical data on the technical efficacy or speed of restoration capabilities, which is better assessed through functional disaster recovery drills.
- ✓
Validate communication and decision-making processes.
Why this is correct
A primary purpose of tabletop exercises is to validate communication and decision-making processes by simulating a crisis scenario in a low-stress, discussion-based environment. Participants articulate their responses, escalation paths, and coordination efforts, allowing facilitators to observe how teams interpret policies, make critical choices, and communicate information under simulated pressure. This helps identify gaps in established procedures, roles, and inter-departmental coordination without impacting live systems.
- ✗
Test technical capabilities of security tools.
Why it's wrong here
Testing the technical capabilities of security tools, such as firewalls, intrusion detection systems, or endpoint protection, requires active deployment, configuration, and observation of their performance against actual or simulated threats. Tabletop exercises are conceptual discussions about *how* tools might be used, but they do not involve the direct interaction, configuration, or performance measurement of these technical controls. Such assessments are typically conducted through technical drills, penetration tests, or red team exercises that engage the tools directly.
- ✗
Identify unpatched vulnerabilities in systems.
Why it's wrong here
Identifying unpatched vulnerabilities in systems is a technical assessment objective typically achieved through automated vulnerability scanning, patch management audits, or penetration testing. These methods involve direct interaction with systems to discover missing security updates, misconfigurations, or exploitable flaws. Tabletop exercises, conversely, focus on human processes, policies, and decision-making during an incident, rather than the technical discovery of system-level security weaknesses.
Go deeper
Related to this question
Learn chapter
Security Assessment and Testing
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.