hardMultiple ChoiceObjective-mapped
CISM Practice Question: A multinational corporation experiences a…
A multinational corporation experiences a security breach involving customer PII. The incident response team needs to determine notification requirements. Which factor is MOST important in deciding which regulatory bodies to inform?
⚠ Common exam trap
The common pitfall in this CISM question is confusing the location of data storage or processing with the residency of the affected individuals. Many candidates incorrectly focus on the data custodian's location, but privacy regulations like GDPR, CCPA, etc., tie notification requirements to the data subjects' location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Location of the affected individuals
Data privacy regulations (e.g., GDPR, CCPA, LGPD) base their notification requirements on the residency or location of the affected data subjects, not on where the breach originated or where the company's executives sit. The incident response team must map the affected PII to the specific jurisdictions whose laws impose breach notification duties, making the location of the affected individuals the primary driver for determining which regulatory bodies to inform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Location of the affected individuals
Why this is correct
Breach notification laws are based on the data subjects' residence.
- ✗
Location of the attacker
Why it's wrong here
Attacker location does not impose notification duties.
- ✗
Location of the company's CIO
Why it's wrong here
CIO location is not a regulatory factor.
- ✗
Location of the data custodian
Why it's wrong here
Data custodian location may not be the affected individuals' jurisdiction.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.