Akylade Certified Cyber Resilience Fundamentals ACCRF · Free Practice Question Medium
Question 10
A startup is currently managing cybersecurity issues on an incident-by-incident basis without any predefined strategy. Most decisions are made spontaneously without consulting any established guidelines or standards. What tier best describes their cybersecurity implementation?
- A Tier 1 (Partial)
- B Tier 4 (Adaptive)
- C Tier 2 (Risk Informed)
- D Tier 3 (Repeatable)
Reveal correct answer
Correct answer: A
Explanation
Tier 1 (Partial) is the best fit as it reflects organizations that manage cybersecurity in an informal, reactive manner, with little to no predetermined strategy or process integration. Tier 4 (Adaptive) characterizes highly mature organizations that proactively adapt their cybersecurity practices based on predictive modeling and ongoing assessments, not relevant to the startup's current practices. Tier 2 (Risk Informed) implies some level of formal risk awareness which is lacking in the startup’s approach, as described. Tier 3 (Repeatable) describes organizations with formalized and consistent cybersecurity practices across the board, which does not match the startup’s ad hoc methods. For support or reporting issues, include Question ID: 661d702e6c62df68d36d7641 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
