Valid CISM Dumps shared by EduDump.com for Helping Passing CISM Exam! EduDump.com now offer the newest CISM exam dumps, the EduDump.com CISM exam questions have been updated and answers have been corrected get the newest EduDump.com CISM dumps with Test Engine here:
A security review identifies that confidential information on the file server has been accessed by unauthorized users in the organization. Which of the following should the information security manager do FIRST?
Correct Answer: A
The first step is to invoke the incident response plan to ensure a systematic, controlled, and compliant response to the security incident. "The incident response plan should be activated immediately to investigate, contain, and resolve incidents of unauthorized access." - CISM Review Manual 15th Edition, Chapter 4: Incident Management, Section: Incident Response Plan Execution* ISACA practice questions also reinforce that invoking the incident response plan is the essential first response to contain the breach.