Courseiva
hardMultiple ChoiceObjective-mapped

CISM Practice Question: A multinational corporation experiences a…

A multinational corporation experiences a security breach involving customer PII. The incident response team needs to determine notification requirements. Which factor is MOST important in deciding which regulatory bodies to inform?

⚠ Common exam trap

The common pitfall in this CISM question is confusing the location of data storage or processing with the residency of the affected individuals. Many candidates incorrectly focus on the data custodian's location, but privacy regulations like GDPR, CCPA, etc., tie notification requirements to the data subjects' location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Location of the affected individuals

Data privacy regulations (e.g., GDPR, CCPA, LGPD) base their notification requirements on the residency or location of the affected data subjects, not on where the breach originated or where the company's executives sit. The incident response team must map the affected PII to the specific jurisdictions whose laws impose breach notification duties, making the location of the affected individuals the primary driver for determining which regulatory bodies to inform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Location of the affected individuals

    Why this is correct

    Breach notification laws are based on the data subjects' residence.

  • Location of the attacker

    Why it's wrong here

    Attacker location does not impose notification duties.

  • Location of the company's CIO

    Why it's wrong here

    CIO location is not a regulatory factor.

  • Location of the data custodian

    Why it's wrong here

    Data custodian location may not be the affected individuals' jurisdiction.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.