ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Legal department
Option C (Legal department) is correct because incident response best practices require immediate legal counsel involvement to assess regulatory notification obligations (e.g., GDPR 72-hour breach reporting, HIPAA, SEC disclosure rules), preserve attorney-client privilege over incident findings, and guide controlled communications that avoid premature or legally risky disclosures. Option D (Executive management) is correct because senior leadership must be notified immediately to authorize containment actions, allocate resources, make strategic decisions about service shutdowns or customer impact, and serve as the approved channel for any external statements. Option A is not correct because notifying all affected customers immediately is premature before the scope, root cause, and legal notification requirements are established, and it risks amplifying the incident. Option B is not correct because issuing a general public press release at the outset can worsen the situation by revealing sensitive details and tipping off attackers. Option E is not correct because law enforcement should be engaged selectively based on jurisdiction, legal guidance, and incident severity, not automatically in every case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All affected customers immediately
Why it's wrong here
Notifying all affected customers immediately risks disclosing unverified details that could escalate the incident, and it bypasses the containment and assessment phases. Customer notification is warranted once scope and impact are confirmed, often after legal and communications review. During active response, internal stakeholders such as the incident response team and management are notified first.
- ✗
General public via press release
Why it's wrong here
A press release reaches everyone, including attackers, and cannot be retracted once sensitive details leak. It is tempting because public disclosure is genuinely required for regulated breaches, transparency duties or reputational repair — but only after containment, legal review and a coordinated communications plan, not during the immediate notification phase.
- ✓
Legal department
Why this is correct
Legal counsel must be engaged immediately because they assess breach-notification duties, preserve attorney-client privilege over incident findings, and approve any external wording before disclosure. This satisfies the stem's constraint of notifying stakeholders without revealing sensitive details that could worsen the situation, since legal review gates what may lawfully and safely be communicated.
- ✓
Executive management
Why this is correct
Executive management requires immediate notification to authorise resources, make business-continuity decisions and own external messaging. Their involvement satisfies the governance requirement that strategic decisions during an incident rest with accountable leadership, not solely technical staff.
- ✗
Local law enforcement automatically
Why it's wrong here
Law enforcement is engaged when the incident meets legal thresholds, jurisdiction, or contractual reporting duties, not automatically at detection. Automatic escalation suits criminal activity such as extortion, intrusion, or data theft requiring investigation and prosecution.
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.