hardMultiple ChoiceObjective-mapped
CISM Practice Question: A financial institution has an incident involving…
A financial institution has an incident involving a suspected data breach of customer PII. The incident response team contains the breach. What should be the NEXT priority according to legal and regulatory requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess the extent of the breach.
After containment, legal and regulatory requirements typically mandate assessing the scope and impact of the breach to determine notification obligations and regulatory reporting. This assessment is critical for prioritizing next steps such as customer notification (C) and public relations (B), which follow after the extent is known. Root cause analysis (D) is important but is a later step in the incident management process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assess the extent of the breach.
Why this is correct
Needed to determine legal notification requirements.
- ✗
Engage a public relations firm.
Why it's wrong here
Not a priority at this stage.
- ✗
Notify affected customers.
Why it's wrong here
Premature without knowing full scope.
- ✗
Perform a root cause analysis.
Why it's wrong here
Should be done after containment and assessment.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.