NIST CSF Practice Question: Which stakeholders should typically be included in incident response... | CyberCertPrep
NISTNIST CSFRespond FunctionEASYFree question
Which stakeholders should typically be included in incident response communications?
A.Only external auditors
B.Only the IT department
C.Only the CEO and board of directors
D.Internal teams, management, legal, and potentially external parties like law enforcement
Why D is correct
Effective incident response requires communication with a range of stakeholders including internal teams, management, legal counsel, and when appropriate, external entities such as law enforcement or regulators.
Know someone studying for NIST CSF? Send them this one.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What is the relationship between the Respond and Detect functions in NIST CSF?