Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 402 discussion

Actual exam question from Isaca's CISM
Question #: 402
Topic #: 1
[All CISM Questions]

During the response to a serious security breach, who is the BEST organizational staff member to communicate with external entities?

  • A. The resource designated by senior management
  • B. The incident response team leader
  • C. The resource specified in the incident response plan
  • D. A dedicated public relations spokesperson
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aokisan
Highly Voted 1 year, 11 months ago
Selected Answer: C
in the response plan, it will be decided.
upvoted 11 times
...
beever
Highly Voted 1 year, 9 months ago
Selected Answer: D
It should be D - A dedicated public relations spokesperson From CISM RM 16th, Public relations (PR) representative will provide controlled communication to internal and external stakeholders to minimize any adverse impact
upvoted 9 times
...
Booict
Most Recent 2 months, 2 weeks ago
Selected Answer: A
A - During a serious security breach, the information being communicated is often highly sensitive and technical, so option A is the best option.
upvoted 1 times
...
Manix
10 months ago
Selected Answer: C
Ext entitties can be public, regulatory, law enforcement,... it's sefined in plan
upvoted 1 times
...
jcisco123
10 months, 4 weeks ago
Selected Answer: C
response plan
upvoted 1 times
...
POWNED
11 months, 3 weeks ago
We dont know the context of the situation, with the information given the best answer is to review the incident response plan to see who is responsible in communicating such an incident. You are going to want a SME to communicate with external parties, it's not always going to be the same person.
upvoted 2 times
...
Ricky_Bobby
1 year, 1 month ago
I think the answer is C, as for a serious cyber incident an organisation may want the CEO to communicate with the Media, Reg affairs will deal with regulatory authorities , so whatever is in the incident plan based on the level of incident.
upvoted 2 times
...
sphenixfire
1 year, 2 months ago
Selected Answer: C
cism aio 2nd: risis communications often establishes relationships with internal and external parties such as investor relations, public safety, and news media. Policy related to crisis manage- ment and crisis communications should define the personnel authorized to communi- cate with external parties. But even then, an organization’s top executives may often be required to approve individual external communications.
upvoted 1 times
...
Agamennore
1 year, 2 months ago
Selected Answer: C
It’s important that there is a chapter in the incident response plan dedicated to communication. I don’t agree with “D” because is not even requested a “public” communication, just for example for incidents that the management want to communicate just to some stakeholders or external entities
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Selected Answer: C
if external entities are third parties it's C
upvoted 1 times
...
richck102
1 year, 5 months ago
D. A dedicated public relations spokesperson
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: A
senior management have the ultimate responsibility. Whoever they decide to communicate will override all the others
upvoted 2 times
...
cangurer
1 year, 8 months ago
Selected Answer: C
I would choose C. A and D should be defined in the incident response plan
upvoted 1 times
...
CarlLimps
1 year, 8 months ago
Selected Answer: A
A. So for all of those below, your telling me you would ignore senior management on identifying who the person/people should be to speak to external entities? I'm going with what senior management says.
upvoted 1 times
CarlLimps
1 year, 8 months ago
I'll go with C. C should be who senior management appoints as they would review the IRP and be aware of the designee. ALSO senior mgmt could have identified this person as a PR firm. So C, what's documented in the incident response plan. GO C!
upvoted 1 times
...
...
MyKasala
1 year, 10 months ago
Selected Answer: C
C is correct
upvoted 2 times
...
EZPASS
2 years ago
Selected Answer: D
I also go with D.
upvoted 4 times
...
Ziggybooboo
2 years ago
Agreed
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...