The board has asked the information security manager to demonstrate that the organisation can actually detect and respond to a realistic, multi-stage attack against production systems, not merely discuss a scenario. Which testing approach is most appropriate to satisfy this request?
- AA red team engagement that emulates a realistic adversary across multiple stages to test the blue team's detection and response Correct
- BA tabletop exercise in which executives talk through how they would respond to a hypothetical ransomware outbreak
- CA vulnerability scan of the production estate with the results presented to the board as evidence of readiness
- DA configuration audit that compares production system settings against the approved hardening baseline
Why A is correct: A red team safely emulates a multi-stage adversary against production to measure whether monitoring detects the activity and the response team reacts, directly demonstrating real detection and response capability.
Why B is wrong: A tabletop is discussion-based and useful for governance awareness, but it cannot demonstrate genuine detection and response capability against live systems, which is precisely what the board asked to see.
Why C is wrong: A vulnerability scan enumerates weaknesses but does not emulate an attacker or test whether the response team detects and reacts, so it does not demonstrate response capability.
Why D is wrong: A configuration audit confirms systems match a baseline, which is sound preventive hygiene, but it is a static check that tests no detection or response behaviour and so misses the board's request.