Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

An organization has experienced a data breach involving customer personally identifiable information (PII). The incident response team has completed containment and eradication. Legal counsel advises that the breach may trigger notification requirements under multiple jurisdictions. Which of the following should the security manager do NEXT to ensure compliance?

⚠ Common exam trap

The trap here is rushing to notify customers or the public without first determining the scope of the breach, which can lead to non-compliant or inaccurate notifications and unnecessary panic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a thorough impact assessment to determine the scope and nature of the data involved.

After containment and eradication, the next critical step in a data breach involving PII is to assess the scope and impact. This assessment identifies which data elements were exposed, how many individuals are affected, and which jurisdictions' laws apply. It provides the factual basis for legal notification decisions and ensures that notifications are accurate, timely, and compliant with varying regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete all compromised data to prevent further exposure.

    Why it's wrong here

    Deleting compromised data does not undo the breach and may destroy evidence needed for investigation and regulatory reporting. It could also violate data retention requirements. The focus should be on assessing the impact and notifying as required, not on destroying data. Evidence preservation is essential for legal and regulatory purposes.

  • ✓

    Conduct a thorough impact assessment to determine the scope and nature of the data involved.

    Why this is correct

    Before notifying regulators or affected individuals, the organization must understand exactly what data was compromised, how many records, and which jurisdictions are affected. This impact assessment informs legal notification obligations and the content of notifications. It is a critical step to ensure accurate and compliant reporting, and it aligns with CISM's emphasis on risk assessment and legal coordination during incident recovery.

  • ✗

    Publicly announce the breach on the company website to demonstrate transparency.

    Why it's wrong here

    Public disclosure without a coordinated communication strategy and legal review can lead to reputational damage, legal risks, and inconsistent messaging. Notification should follow legal requirements and a communication plan. The security manager should first assess the impact and work with legal and communications teams to determine the appropriate disclosure method and timing.

  • ✗

    Immediately send a blanket notification to all customers regardless of jurisdiction.

    Why it's wrong here

    A blanket notification without understanding the scope may be premature, cause unnecessary panic, and fail to meet specific jurisdictional requirements. Notification laws vary and may require specific content, timing, and recipients. Sending a generic notice could also create legal liability if it misstates facts. The organization should first assess the impact to tailor notifications appropriately.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.