exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 543 discussion

Actual exam question from Isaca's CISM
Question #: 543
Topic #: 1
[All CISM Questions]

Which of the following is an information security manager's BEST course of action when a potential business breach is discovered in a critical business system?

  • A. Update the incident response plan.
  • B. Inform affected stakeholders.
  • C. Inform IT management.
  • D. Implement mitigating actions immediately.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cosmo4ng
Highly Voted 1 year, 5 months ago
Selected Answer: B
Agreed. Inform affected stakeholders first incase implementing mitigating actions affects operation of their systems.
upvoted 8 times
...
SHERLOCKAWS
Most Recent 1 week ago
Selected Answer: D
Answer is D: because when dealing with a critical business system, speed and containment are essential to minimize potential damage, even if the breach is not fully confirmed yet. This aligns with the CISM principle of taking swift, risk-based action to protect the organization while confirming and escalating appropriately afterward.
upvoted 1 times
SHERLOCKAWS
1 day, 15 hours ago
I reconsider answer is B. Inform affected stakeholders, this before any mitigation.
upvoted 1 times
...
...
Salilgen
7 months ago
Selected Answer: C
Before informing stakeholders or implementing mitigation actions, you should check whether there actually is a problem. To carry out this verification, you should inform the IT manager. IMO answer is C
upvoted 1 times
...
TamerBeSafe
8 months, 1 week ago
Selected Answer: A
A. Update the incident response plan. While it might be tempting to jump to implementing mitigating actions immediately (Option D), it is crucial to follow a structured and well-defined incident response process. Updating the incident response plan is a critical step because it ensures that the organization is well-prepared to handle the specific nature of the breach. This includes identifying the scope of the incident, assessing the impact, determining the appropriate response actions, and coordinating communication with stakeholders.
upvoted 1 times
ee1a5de
2 months ago
I was going to agree with you, but this option states "UPDATES the incident response plan", it would have been the best suited option if it stated "Implement the incident response plan". I think informing the affected stakeholders would be the best course of action in this instance.
upvoted 1 times
...
...
POWNED
9 months ago
Selected Answer: B
POTENTIAL, need to confirm it is a breach before rolling into remediation.
upvoted 2 times
...
jcisco123
9 months, 1 week ago
Selected Answer: B
It is a 'potential' breach - not confirmed that it is actually a breach. Inform the stakeholder first. Immediate mitigation (D) is important but it should be carried out as part of a coordinated effort once stakeholders, including IT management and security teams, are informed and engaged. Ideally there should be an option to check and validate if the breach has actually happened or not.
upvoted 1 times
...
koala_lay
1 year ago
Selected Answer: D
As an information security manager, the best course of action when a potential business breach is discovered in a critical business system would be to implement mitigating actions immediately. Option D is the correct answer. Taking immediate action to contain and mitigate the breach can help prevent further damage or loss of data. This includes isolating affected systems, patching vulnerabilities, and conducting a thorough investigation. Once the situation is under control, it is also important to update the incident response plan (option A), inform affected stakeholders (option B), and inform IT management (option C). However, the first priority should be to take immediate action to limit the impact of the breach.
upvoted 1 times
...
oluchecpoint
1 year ago
Selected Answer: B
Option B
upvoted 1 times
...
AaronS1990
1 year, 1 month ago
I misread and didn't realise at this stage it is only a potential issue. I think it's a shit question because: Why tell stakeholders when there isn't definitely an issue? Why begin mitigation efforts if there may not be an issue? You wouldn't do either.
upvoted 3 times
...
AaronS1990
1 year, 1 month ago
Selected Answer: D
I'm surprised to see that there is no confirmatory option and so I would go for D. The most important thing you can get started with now is containing any.
upvoted 1 times
...
drewl25
1 year, 1 month ago
Selected Answer: D
why would you tell the stakeholders? what are they going to do??? the BEST course of action for an information security manager when a potential business breach is discovered in a critical business system is to implement mitigating actions immediately, aligning with the Incident Management domain. Immediate action is necessary to protect critical systems, prevent escalation, and minimize the impact of the breach.
upvoted 2 times
...
Goseu
1 year, 2 months ago
Selected Answer: B
B. Is the correct answer. Think like a manager .
upvoted 1 times
...
richck102
1 year, 3 months ago
B. Inform affected stakeholders.
upvoted 1 times
...
Saisharan
1 year, 3 months ago
Option D
upvoted 2 times
...
Broesweelies
1 year, 7 months ago
Selected Answer: D
D. Implement mitigating actions immediately.
upvoted 2 times
...
bambs
1 year, 8 months ago
Selected Answer: D
The best course of action is to take immediate and appropriate steps to contain and mitigate the damage and to preserve evidence for further investigation.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago