Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?

⚠ Common exam trap

The trap here is assuming that technical indicators like malware type or failed login counts determine severity, when severity must be driven by business and regulatory impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The potential business impact and regulatory notification obligations arising from the exposed records

Severity levels exist to drive escalation, resource allocation, and executive notification. The determinant must be the consequence to the business, including legal and regulatory exposure. With confirmed unauthorized access to payment card data, notification obligations and financial impact are concrete and significant. Technical indicators such as failed logins, malware family, or acknowledgment time inform response but do not define the severity of the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The specific malware family or attacker tooling identified during initial triage

    Why it's wrong here

    Identifying the malware family or tooling helps with containment and threat intelligence, but it does not determine severity. Two different malware strains can cause identical business impact. CISM guidance places attacker attributes below impact assessment in priority because severity is about consequence to the enterprise, not about the technical characteristics of the intrusion.

  • ✗

    The number of failed login attempts recorded before the successful breach

    Why it's wrong here

    Failed login attempts are a useful detection signal, but they do not measure the business impact of a confirmed breach. Severity classification in CISM focuses on the actual or potential harm to the organization and its stakeholders. The volume of failed attempts could be high from scanning activity or low from a targeted attack, so it is unreliable as a severity driver here.

  • ✓

    The potential business impact and regulatory notification obligations arising from the exposed records

    Why this is correct

    Severity classification must reflect the business impact, including regulatory, financial, and reputational consequences. Exposure of payment card data triggers mandatory notification and potential fines under PCI DSS and privacy regulations. CISM emphasizes that incident prioritization is driven by impact to the organization, not by technical metrics alone, making this the primary factor for assigning severity.

  • ✗

    The elapsed time between the first alert and the analyst's acknowledgment of the ticket

    Why it's wrong here

    Mean time to acknowledge is a performance metric for the SOC, not a severity driver. A fast acknowledgment does not reduce the impact of 50,000 exposed records. Conversely, a slow acknowledgment of a trivial event does not make it severe. CISM distinguishes operational metrics from impact-based classification criteria when defining incident severity levels.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.