Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

⚠ Common exam trap

CC often tests the boundaries of what should be included in initial crisis communication, and candidates may incorrectly include technical details or customer information, confusing the need for transparency with the need for confidentiality and security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A statement that a disaster has been declared

Option A is correct because the initial crisis communication must explicitly state that a disaster has been declared, which formally triggers the DRP and informs stakeholders that recovery procedures are now in effect. Option C is correct because providing contact information for the incident response team ensures that responders and key personnel can be reached immediately to coordinate recovery activities. Option D is correct because instructing employees to work remotely helps maintain business continuity and safety by directing staff away from potentially affected facilities. Option B is not included because details of the exploited vulnerability are typically investigated and disclosed later by security or forensic teams, not in the initial crisis notification. Option E is also not included because naming affected customers raises privacy and legal concerns and is not part of the immediate internal crisis communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A statement that a disaster has been declared

    Why this is correct

    The initial crisis communication must formally announce that a disaster has been declared, triggering DRP activation and mobilising response teams. Without this declaration, staff and stakeholders lack the authoritative signal that normal operations are suspended and recovery procedures now govern.

  • ✗

    Details of the vulnerability exploited

    Why it's wrong here

    Crisis communication during DRP activation addresses impact, status and recovery actions, not attack forensics. Vulnerability details belong in a post-incident root-cause report once services are restored. It tempts because breach notifications and security incident reports do document exploited weaknesses — correct when the trigger is a confirmed compromise rather than a power outage.

  • ✓

    Contact information for the incident response team

    Why this is correct

    Contact details for the incident response team let recipients reach the people coordinating recovery, ensuring escalations and status updates flow through the correct channels. This satisfies the stem's requirement that initial crisis communication enable immediate, directed coordination after the outage.

  • ✓

    Instructions for employees to work remotely

    Why this is correct

    Instructing employees to work remotely maintains business function during the power outage by relocating work to unaffected locations. This directly supports continuity, since staff cannot occupy a site lacking power, and it belongs in the initial communication to prevent idle downtime.

  • ✗

    Names of affected customers

    Why it's wrong here

    Naming affected customers exposes personal data and unverified impact during an unfolding outage, creating legal and reputational risk. Initial crisis communication covers incident status, safety, and contacts. Customer names belong in later, verified notifications once scope is confirmed.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.