Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)

⚠ Common exam trap

CC often tests the ordering of incident notifications — candidates incorrectly include affected customers or law enforcement in the 'initial' tier, when best practice places them in later, post-assessment tiers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Legal department

Legal department (A) must be included in initial notifications because they assess regulatory and contractual breach-notification obligations, preserve legal privilege, and guide the organization on disclosure requirements that may carry statutory deadlines. Internal management (B) is essential because executives and incident-response leadership need immediate situational awareness to authorize containment actions, allocate resources, and make business-impact decisions. Public relations (E) belongs in the initial notification group because they control the organization's external messaging, prepare holding statements, and prevent inconsistent or damaging communications while facts are still being verified. Affected customers (C) are typically notified only after the scope and impact are confirmed and legal/PR messaging is prepared, so they are not part of the initial internal notification wave. Law enforcement (D) is engaged selectively depending on the incident type, jurisdiction, and whether criminal activity or regulatory reporting mandates apply, so it is not always an initial notification recipient.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Legal department

    Why this is correct

    Legal must be notified immediately because initial breach communications can create legal obligations and privilege considerations. Involving counsel early preserves attorney-client privilege over incident findings and ensures notifications meet regulatory and contractual duties, satisfying the stem's requirement that crisis communications follow established best practise during a live security incident.

  • ✓

    Internal management

    Why this is correct

    Internal management must always be notified during incident escalation, satisfying the stem's requirement for initial stakeholder notification. They hold decision-making authority over containment, resource allocation and external messaging, so withholding early notification delays the response and risks uncoordinated disclosure. This makes internal management one of the three mandatory groups.

  • ✗

    Affected customers

    Why it's wrong here

    Affected customers are notified after initial containment and assessment, not in the first wave, which targets internal responders and leadership. Notifying them early is tempting because transparency builds trust, and it is correct once impact is confirmed and messaging is approved.

  • ✗

    Law enforcement

    Why it's wrong here

    Law enforcement is engaged only when the incident meets legal or regulatory thresholds, not automatically in initial notifications. It tempts because breach response often involves police or regulators, and involving them is correct once criminal activity or mandatory reporting obligations are confirmed.

  • ✓

    Public relations

    Why this is correct

    Public relations belongs in initial notifications because the crisis team needs controlled external messaging before rumour spreads. This satisfies the stem's requirement to notify stakeholders during a security incident: PR coordinates disclosure to media, customers and regulators, aligning communication with legal and executive decisions rather than letting unverified details leak.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.