mediumMultiple SelectObjective-mapped
CISM Practice Question: Experiences a data breach involving personal…
An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)
⚠ Common exam trap
CISM often tests the misconception that immediate public disclosure or log deletion is acceptable, but the trap here is confusing 'transparency' with 'legal notification' and 'evidence preservation' with 'security through obscurity'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify the relevant data protection authority within the required timeframe.
Data breach notification laws (e.g., GDPR Article 33, CCPA) require organizations to notify the relevant data protection authority within a specified timeframe (e.g., 72 hours under GDPR) once the breach is confirmed. This is a mandatory legal obligation in incident response to avoid penalties and demonstrate regulatory compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately issue a press release without consulting legal.
Why it's wrong here
Issuing a press release without legal consultation could lead to inaccurate statements, liability issues, and violation of confidentiality. The correct procedure is to consult legal and public relations before any public disclosure.
- ✓
Notify the relevant data protection authority within the required timeframe.
Why this is correct
Under data breach notification laws (e.g., GDPR, CCPA), organizations must notify the appropriate authority within a specified timeframe (e.g., 72 hours under GDPR) to comply with legal obligations.
- ✗
Ignore the incident if no customers have complained.
Why it's wrong here
Ignoring an incident is unacceptable. Even without customer complaints, the organization must investigate and respond appropriately to mitigate risks and comply with legal requirements.
- ✓
Conduct a post-incident review to identify lessons learned.
Why this is correct
Post-incident review is a critical step in incident response to improve future response efforts and prevent recurrence. It helps capture lessons learned.
- ✗
Delete all system logs to prevent further exposure.
Why it's wrong here
Deleting logs destroys evidence and violates preservation requirements. Logs are crucial for forensic analysis and legal proceedings.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.