CISM Incident Management Practice Question
A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?
⚠ Common exam trap
The trap here is assuming that technical indicators like malware type or failed login counts determine severity, when severity must be driven by business and regulatory impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The potential business impact and regulatory notification obligations arising from the exposed records
Severity levels exist to drive escalation, resource allocation, and executive notification. The determinant must be the consequence to the business, including legal and regulatory exposure. With confirmed unauthorized access to payment card data, notification obligations and financial impact are concrete and significant. Technical indicators such as failed logins, malware family, or acknowledgment time inform response but do not define the severity of the incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The specific malware family or attacker tooling identified during initial triage
Why it's wrong here
Identifying the malware family or tooling helps with containment and threat intelligence, but it does not determine severity. Two different malware strains can cause identical business impact. CISM guidance places attacker attributes below impact assessment in priority because severity is about consequence to the enterprise, not about the technical characteristics of the intrusion.
- ✗
The number of failed login attempts recorded before the successful breach
Why it's wrong here
Failed login attempts are a useful detection signal, but they do not measure the business impact of a confirmed breach. Severity classification in CISM focuses on the actual or potential harm to the organization and its stakeholders. The volume of failed attempts could be high from scanning activity or low from a targeted attack, so it is unreliable as a severity driver here.
- ✓
The potential business impact and regulatory notification obligations arising from the exposed records
Why this is correct
Severity classification must reflect the business impact, including regulatory, financial, and reputational consequences. Exposure of payment card data triggers mandatory notification and potential fines under PCI DSS and privacy regulations. CISM emphasizes that incident prioritization is driven by impact to the organization, not by technical metrics alone, making this the primary factor for assigning severity.
- ✗
The elapsed time between the first alert and the analyst's acknowledgment of the ticket
Why it's wrong here
Mean time to acknowledge is a performance metric for the SOC, not a severity driver. A fast acknowledgment does not reduce the impact of 50,000 exposed records. Conversely, a slow acknowledgment of a trivial event does not make it severe. CISM distinguishes operational metrics from impact-based classification criteria when defining incident severity levels.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.