Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Legal department

Option C (Legal department) is correct because incident response best practices require immediate legal counsel involvement to assess regulatory notification obligations (e.g., GDPR 72-hour breach reporting, HIPAA, SEC disclosure rules), preserve attorney-client privilege over incident findings, and guide controlled communications that avoid premature or legally risky disclosures. Option D (Executive management) is correct because senior leadership must be notified immediately to authorize containment actions, allocate resources, make strategic decisions about service shutdowns or customer impact, and serve as the approved channel for any external statements. Option A is not correct because notifying all affected customers immediately is premature before the scope, root cause, and legal notification requirements are established, and it risks amplifying the incident. Option B is not correct because issuing a general public press release at the outset can worsen the situation by revealing sensitive details and tipping off attackers. Option E is not correct because law enforcement should be engaged selectively based on jurisdiction, legal guidance, and incident severity, not automatically in every case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All affected customers immediately

    Why it's wrong here

    Notifying all affected customers immediately risks disclosing unverified details that could escalate the incident, and it bypasses the containment and assessment phases. Customer notification is warranted once scope and impact are confirmed, often after legal and communications review. During active response, internal stakeholders such as the incident response team and management are notified first.

  • ✗

    General public via press release

    Why it's wrong here

    A press release reaches everyone, including attackers, and cannot be retracted once sensitive details leak. It is tempting because public disclosure is genuinely required for regulated breaches, transparency duties or reputational repair — but only after containment, legal review and a coordinated communications plan, not during the immediate notification phase.

  • ✓

    Legal department

    Why this is correct

    Legal counsel must be engaged immediately because they assess breach-notification duties, preserve attorney-client privilege over incident findings, and approve any external wording before disclosure. This satisfies the stem's constraint of notifying stakeholders without revealing sensitive details that could worsen the situation, since legal review gates what may lawfully and safely be communicated.

  • ✓

    Executive management

    Why this is correct

    Executive management requires immediate notification to authorise resources, make business-continuity decisions and own external messaging. Their involvement satisfies the governance requirement that strategic decisions during an incident rest with accountable leadership, not solely technical staff.

  • ✗

    Local law enforcement automatically

    Why it's wrong here

    Law enforcement is engaged when the incident meets legal thresholds, jurisdiction, or contractual reporting duties, not automatically at detection. Automatic escalation suits criminal activity such as extortion, intrusion, or data theft requiring investigation and prosecution.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.