CISM · Question #197
After detecting an advanced persistent threat (APT), which of the following should be the information security manager's FIRST step?
The correct answer is C. Notify affected stakeholders.. After confirming an APT, the first step is to notify affected stakeholders - including executive leadership, legal counsel, and potentially regulators - because APT response requires coordinated authorization, resources, and possibly mandatory breach notification within regulator
Question
After detecting an advanced persistent threat (APT), which of the following should be the information security manager's FIRST step?
Options
- AConduct a vulnerability analysis.
- BRemove the threat.
- CNotify affected stakeholders.
- DPerform a root cause analysis.
How the community answered
(50 responses)- A6% (3)
- B2% (1)
- C78% (39)
- D14% (7)
Explanation
After confirming an APT, the first step is to notify affected stakeholders - including executive leadership, legal counsel, and potentially regulators - because APT response requires coordinated authorization, resources, and possibly mandatory breach notification within regulatory timeframes. Acting before notifying (e.g., removing the threat immediately) risks destroying forensic evidence and bypassing required approvals. Root cause analysis (D) and vulnerability analysis (A) are important but come after the response is properly authorized and coordinated. Removing the threat (B) prematurely can also alert the attacker to cover their tracks.
Topics
Community Discussion
No community discussion yet for this question.