nerdexam
Isaca

CISM · Question #983

A security review of an HR application reveals a file server containing confidential HR data is accessible to external user IDs. Which of the following should the information security manager do…

The correct answer is D. Remove access permissions for the external users. When confidential data is actively exposed, the first priority is containment - stop the bleeding immediately. Removing external access permissions eliminates the ongoing risk without delay. Confirming with the data owner (B) introduces unnecessary lag while the exposure…

Submitted by jian89· Apr 18, 2026Information Security Incident Management

Question

A security review of an HR application reveals a file server containing confidential HR data is accessible to external user IDs. Which of the following should the information security manager do FIRST?

Options

  • AUpdate the existing data privacy policy.
  • BConfirm the issue with the data owner.
  • CTrain the HR team on proper access control.
  • DRemove access permissions for the external users.

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    25% (8)
  • C
    16% (5)
  • D
    50% (16)

Explanation

When confidential data is actively exposed, the first priority is containment - stop the bleeding immediately. Removing external access permissions eliminates the ongoing risk without delay. Confirming with the data owner (B) introduces unnecessary lag while the exposure continues. Updating the data privacy policy (A) and training the HR team (C) are corrective and preventive actions that address root causes but do not stop the immediate harm. Security incident response follows: contain first, then investigate, then remediate systemic issues.

Topics

#Access Control#Incident Response#Risk Mitigation#Data Protection

Community Discussion

No community discussion yet for this question.

Full CISM Practice