nerdexam
Isaca

CISM · Question #197

After detecting an advanced persistent threat (APT), which of the following should be the information security manager's FIRST step?

The correct answer is C. Notify affected stakeholders.. After confirming an APT, the first step is to notify affected stakeholders - including executive leadership, legal counsel, and potentially regulators - because APT response requires coordinated authorization, resources, and possibly mandatory breach notification within regulator

Submitted by viktor_hu· Apr 18, 2026Information Security Incident Management

Question

After detecting an advanced persistent threat (APT), which of the following should be the information security manager's FIRST step?

Options

  • AConduct a vulnerability analysis.
  • BRemove the threat.
  • CNotify affected stakeholders.
  • DPerform a root cause analysis.

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    78% (39)
  • D
    14% (7)

Explanation

After confirming an APT, the first step is to notify affected stakeholders - including executive leadership, legal counsel, and potentially regulators - because APT response requires coordinated authorization, resources, and possibly mandatory breach notification within regulatory timeframes. Acting before notifying (e.g., removing the threat immediately) risks destroying forensic evidence and bypassing required approvals. Root cause analysis (D) and vulnerability analysis (A) are important but come after the response is properly authorized and coordinated. Removing the threat (B) prematurely can also alert the attacker to cover their tracks.

Topics

#Incident Response#APT#Stakeholder Communication#Incident Management Process

Community Discussion

No community discussion yet for this question.

Full CISM Practice