hardMultiple Choice
CISM Practice Question: During a cyber incident, the organization's legal…
During a cyber incident, the organization's legal counsel advises that certain information about the breach should not be shared with external partners due to ongoing law enforcement investigation. The incident response team must balance transparency with confidentiality. Which of the following is the BEST approach?
⚠ Common exam trap
It's easy for candidates to choose Option B (share all under NDA) because they assume legal agreements override all other constraints, failing to recognize that law enforcement investigations and preservation orders take precedence over contractual confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide only non-sensitive overview to partners
It allows the incident response team to maintain necessary transparency with external partners while respecting legal counsel's directive to withhold sensitive details due to an ongoing law enforcement investigation. Providing a non-sensitive overview—such as the general nature of the incident, affected systems (without PII), and remediation timeline—fulfills partnership obligations without jeopardizing the investigation or violating chain-of-custody requirements for digital forensics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Seek partner input on what to share
Why it's wrong here
Deferring to partners on disclosure scope cedes the decision to parties outside the investigation, overriding legal counsel's restriction. Consulting partners suits coordinated response where no legal hold exists; here counsel's instruction governs what may be shared.
- ✗
Share all information with partners under NDA
Why it's wrong here
Sharing everything under NDA still discloses details that legal counsel has restricted to protect the law enforcement investigation, risking evidence integrity and legal exposure. NDA-based sharing suits routine partner notification where no legal hold or disclosure restriction applies.
- ✓
Provide only non-sensitive overview to partners
Why this is correct
Providing only a non-sensitive overview satisfies legal counsel's confidentiality constraint while preserving partner awareness. This partial-disclosure approach shares sanitised indicators without revealing law-enforcement-sensitive details, balancing transparency with the investigation's integrity. It avoids full disclosure that could compromise the probe, and avoids total silence that would breach partner obligations.
- ✗
Withhold all information until investigation ends
Why it's wrong here
Withholding all information for the duration of a law-enforcement investigation, which can run for months, risks breaching contractual notification obligations many partner agreements include and erodes trust with no clear end date. Providing a non-sensitive overview satisfies typical notification requirements while excluding the specific details legal counsel flagged as sensitive.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.