CIM Crisis Communication & Notifications 5 ā Questions and Answers
Question 1: What is 'social media monitoring' most useful for during a public-facing incident?
- Automatically resolving technical issues identified in customer tweets
- Detecting real-time public sentiment, spread of misinformation, and emerging concerns (Correct answer)
- Identifying which employees violated data confidentiality policies
- Generating automated responses approved by legal teams
Correct answer: Detecting real-time public sentiment, spread of misinformation, and emerging concerns
Social media monitoring lets the crisis team track public perception, catch inaccurate narratives early, and respond before misinformation spreads widely.
Question 2: A 'communication blackout' during an incidentāwhere no updates are sentāis MOST likely to cause:
- Improved focus for the technical resolution team
- Speculation, rumors, and loss of stakeholder confidence (Correct answer)
- Reduced volume of inbound support calls from customers
- Faster incident resolution due to reduced distraction
Correct answer: Speculation, rumors, and loss of stakeholder confidence
Silence creates an information vacuum that stakeholders fill with speculation, often amplifying anxiety and reputational damage.
Question 3: When an incident affects multiple regions with different regulatory requirements, which factor MOST influences notification timing?
- The severity classification assigned by the Incident Commander
- The strictest applicable regulatory deadline across all affected jurisdictions (Correct answer)
- The organization's standard SLA with each regional customer
- The preference of the regional account management teams
Correct answer: The strictest applicable regulatory deadline across all affected jurisdictions
Organizations must comply with the most stringent regulatory timeline to avoid violations; this often drives the overall notification schedule.
Question 4: What is the difference between a 'notification' and an 'escalation' in incident communications?
- Notifications inform; escalations request a higher authority to take action or make a decision (Correct answer)
- Notifications are automated; escalations are always manual
- Notifications go to customers; escalations go to internal teams only
- Notifications occur at incident start; escalations only occur at resolution
Correct answer: Notifications inform; escalations request a higher authority to take action or make a decision
A notification shares information while an escalation transfers or elevates responsibility and decision-making authority to a senior person or team.
Question 5: Which of the following is a leading practice for post-incident communication to customers?
- Send a brief apology email immediately at resolution with no further follow-up
- Publish a detailed post-incident report (PIR) explaining what happened, why, and what was fixed (Correct answer)
- Provide only the resolution time and avoid discussing the root cause to prevent legal risk
- Send communications only to customers who formally complained during the outage
Correct answer: Publish a detailed post-incident report (PIR) explaining what happened, why, and what was fixed
A published Post-Incident Report demonstrates accountability, builds trust, and shows commitment to preventing recurrence.
Question 6: An organization using an automated mass notification system (MNS) during a Sev-1 incident should ensure the system is configured to:
- Send identical messages to all contacts regardless of role or location
- Target the right audience segments with role-appropriate messages and require acknowledgment (Correct answer)
- Send alerts only during business hours to avoid disturbing off-duty staff
- Limit notifications to no more than three stakeholders to prevent information overload
Correct answer: Target the right audience segments with role-appropriate messages and require acknowledgment
Effective MNS configuration segments audiences by role, tailors message content, and tracks acknowledgment to confirm receipt.
Question 7: What is the purpose of pre-approved message templates in an incident communication plan?
- To eliminate the need for a Communications Lead during incidents
- To reduce drafting time and ensure legally reviewed, consistent messaging under pressure (Correct answer)
- To comply with ISO 27001 documentation requirements for all incidents
- To automate full communication workflows without human review
Correct answer: To reduce drafting time and ensure legally reviewed, consistent messaging under pressure
Pre-approved templates let teams communicate quickly without waiting for on-the-spot legal or PR approval, reducing notification lag during high-pressure situations.
What is 'social media monitoring' most useful for during a public-facing incident?