exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 543 discussion

Actual exam question from Isaca's CISM
Question #: 543
Topic #: 1
[All CISM Questions]

Which of the following is an information security manager's BEST course of action when a potential business breach is discovered in a critical business system?

  • A. Update the incident response plan.
  • B. Inform affected stakeholders.
  • C. Inform IT management.
  • D. Implement mitigating actions immediately.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cosmo4ng
Highly Voted 1 year, 4 months ago
Selected Answer: B
Agreed. Inform affected stakeholders first incase implementing mitigating actions affects operation of their systems.
upvoted 8 times
...
Salilgen
Most Recent 5 months, 3 weeks ago
Selected Answer: C
Before informing stakeholders or implementing mitigation actions, you should check whether there actually is a problem. To carry out this verification, you should inform the IT manager. IMO answer is C
upvoted 1 times
...
TamerBeSafe
7 months, 1 week ago
Selected Answer: A
A. Update the incident response plan. While it might be tempting to jump to implementing mitigating actions immediately (Option D), it is crucial to follow a structured and well-defined incident response process. Updating the incident response plan is a critical step because it ensures that the organization is well-prepared to handle the specific nature of the breach. This includes identifying the scope of the incident, assessing the impact, determining the appropriate response actions, and coordinating communication with stakeholders.
upvoted 1 times
ee1a5de
3 weeks, 5 days ago
I was going to agree with you, but this option states "UPDATES the incident response plan", it would have been the best suited option if it stated "Implement the incident response plan". I think informing the affected stakeholders would be the best course of action in this instance.
upvoted 1 times
...
...
POWNED
8 months ago
Selected Answer: B
POTENTIAL, need to confirm it is a breach before rolling into remediation.
upvoted 2 times
...
jcisco123
8 months ago
Selected Answer: B
It is a 'potential' breach - not confirmed that it is actually a breach. Inform the stakeholder first. Immediate mitigation (D) is important but it should be carried out as part of a coordinated effort once stakeholders, including IT management and security teams, are informed and engaged. Ideally there should be an option to check and validate if the breach has actually happened or not.
upvoted 1 times
...
koala_lay
11 months, 3 weeks ago
Selected Answer: D
As an information security manager, the best course of action when a potential business breach is discovered in a critical business system would be to implement mitigating actions immediately. Option D is the correct answer. Taking immediate action to contain and mitigate the breach can help prevent further damage or loss of data. This includes isolating affected systems, patching vulnerabilities, and conducting a thorough investigation. Once the situation is under control, it is also important to update the incident response plan (option A), inform affected stakeholders (option B), and inform IT management (option C). However, the first priority should be to take immediate action to limit the impact of the breach.
upvoted 1 times
...
oluchecpoint
11 months, 3 weeks ago
Selected Answer: B
Option B
upvoted 1 times
...
AaronS1990
1 year ago
I misread and didn't realise at this stage it is only a potential issue. I think it's a shit question because: Why tell stakeholders when there isn't definitely an issue? Why begin mitigation efforts if there may not be an issue? You wouldn't do either.
upvoted 3 times
...
AaronS1990
1 year ago
Selected Answer: D
I'm surprised to see that there is no confirmatory option and so I would go for D. The most important thing you can get started with now is containing any.
upvoted 1 times
...
drewl25
1 year ago
Selected Answer: D
why would you tell the stakeholders? what are they going to do??? the BEST course of action for an information security manager when a potential business breach is discovered in a critical business system is to implement mitigating actions immediately, aligning with the Incident Management domain. Immediate action is necessary to protect critical systems, prevent escalation, and minimize the impact of the breach.
upvoted 2 times
...
Goseu
1 year, 1 month ago
Selected Answer: B
B. Is the correct answer. Think like a manager .
upvoted 1 times
...
richck102
1 year, 2 months ago
B. Inform affected stakeholders.
upvoted 1 times
...
Saisharan
1 year, 2 months ago
Option D
upvoted 2 times
...
Broesweelies
1 year, 6 months ago
Selected Answer: D
D. Implement mitigating actions immediately.
upvoted 2 times
...
bambs
1 year, 6 months ago
Selected Answer: D
The best course of action is to take immediate and appropriate steps to contain and mitigate the damage and to preserve evidence for further investigation.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago