Isaca
CISM · Question #605
A security review identifies that confidential information on the file server has been accessed by unauthorized users in the organization. Which of the following should the information security…
The correct answer is D. Invoke the incident response plan. The first action should be to invoke the incident response plan to ensure a structured approach to contain, investigate, and remediate the breach while preserving evidence and minimizing impact.
Submitted by eva_at· Apr 18, 2026Information Security Incident Management
Question
A security review identifies that confidential information on the file server has been accessed by unauthorized users in the organization. Which of the following should the information security manager do FIRST?
Options
- ADelete the information from the file server.
- BImplement role-based access control (RBAC).
- CRemove access to the information.
- DInvoke the incident response plan.
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C8% (2)
- D80% (20)
Explanation
The first action should be to invoke the incident response plan to ensure a structured approach to contain, investigate, and remediate the breach while preserving evidence and minimizing impact.
Topics
#Incident response#Unauthorized access#Security incident management#First responder actions
Community Discussion
No community discussion yet for this question.