NIST CSF Practice Question: What type of information should be shared with external stakeholders... | CyberCertPrep
NISTNIST CSFRespond FunctionEASYFree question
What type of information should be shared with external stakeholders during a cybersecurity incident?
A.All technical details of the breach including system passwords
B.Information consistent with response plans, legal requirements, and organizational policies
C.No information should ever be shared externally
D.Only financial impact estimates
Why B is correct
Information shared externally should be consistent with response plans, legal and regulatory requirements, and organizational policies to ensure appropriate disclosure without compromising the investigation.
Know someone studying for NIST CSF? Send them this one.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What is the primary goal of the NIST CSF Respond function?