Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 344 discussion

Actual exam question from Isaca's CISA
Question #: 344
Topic #: 1
[All CISA Questions]

Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?

  • A. Industry standards
  • B. Information security policy
  • C. Incident response plan
  • D. Industry regulations
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
musat
3 months, 3 weeks ago
Selected Answer: C
After a security breach, you don't look at industry regulations, you go and find out the time required from the incident response plan. But in the first place, this information enters the incident response plan from industry regulations
upvoted 1 times
...
analuisamoreira
4 months, 3 weeks ago
Selected Answer: C
This is not subject of industry regulations.
upvoted 1 times
...
46080f2
5 months, 3 weeks ago
Selected Answer: C
C. is correct: “Following a breach ,..” is the key phrase here. It is about the best source for an urgent operational action and not about which is the best source to create the incident response plan. A Google search with operator 'site:isaca.org' and search term 'incident response plan' gives us an ISACA QAE compliant answer. An incident response plan has to be created according to different ‘incident response models’ depending on the industry. In other words, by the time the operational issue arises, the industry-related regulations have long been integrated into the incident response plan and the only thing left to do is to act accordingly. And the best source for this at the time of "following a breach..." is the incident response plan.
upvoted 3 times
...
kGiGa
12 months ago
Who should know the maximum time? The regulator, the auditor or the person who responsible for handling the incident?
upvoted 1 times
...
starzuu
1 year, 4 months ago
Selected Answer: D
i think D makes more sense. Regulations would matter more when it comes to deciding the maximum.
upvoted 4 times
...
AliHamza
1 year, 4 months ago
C is correct. When you create incident response plan you add this detail
upvoted 1 times
...
3008
1 year, 5 months ago
Selected Answer: D
the best source to determine the maximum amount of time before customers must be notified after a data breach is industry regulations.
upvoted 1 times
...
ItsBananass
1 year, 5 months ago
Following a breach, what is the BEST SOURCE to determine the maximum amount ...
upvoted 1 times
ItsBananass
1 year, 5 months ago
I think the source is the incident response plan. While dealing with an incident do you want to look up breach notification research, best practices, industry standards and my not be right for your company.
upvoted 1 times
...
...
testhongbrian
1 year, 7 months ago
D for sure
upvoted 1 times
...
Eric0223
1 year, 9 months ago
regulartion should be top priority than others, otherwise, what s the point of this notifcation sooner or later?
upvoted 1 times
...
Julianleehk
2 years, 1 month ago
The question talking about breach, C could be correct.
upvoted 1 times
...
MunaM
2 years, 2 months ago
answer should be D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...