nerdexam
Isaca

CISM · Question #685

Which of the following should be an information security manager's FIRST course of action when a potential business breach is discovered in a critical business system?

The correct answer is C. Validate the breach.. Before taking further action, the information security manager must first validate the breach to confirm its authenticity and scope. This ensures that appropriate and proportionate response measures are taken.

Submitted by zhang_li· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be an information security manager’s FIRST course of action when a potential business breach is discovered in a critical business system?

Options

  • AInform senior management of the breach.
  • BImplement mitigating actions immediately.
  • CValidate the breach.
  • DInvoke the incident response plan.

How the community answered

(14 responses)
  • A
    7% (1)
  • C
    86% (12)
  • D
    7% (1)

Explanation

Before taking further action, the information security manager must first validate the breach to confirm its authenticity and scope. This ensures that appropriate and proportionate response measures are taken.

Topics

#Incident Response#Breach Detection#Incident Validation#First Response Actions

Community Discussion

No community discussion yet for this question.

Full CISM Practice