CISM Incident Management Practice Question
A security manager is drafting the incident classification criteria for a new incident response plan. Executive leadership has asked how the team will decide, in the first few minutes of an event, whether to invoke the crisis management team. Which of the following is the MOST appropriate basis for that initial escalation decision?
⚠ Common exam trap
The trap here is assuming that a dramatic technical signal, such as a high alert count, automatically indicates a high-severity incident requiring executive escalation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The predefined severity level assigned to the incident type and its assessed business impact
Incident classification must be anchored to predefined severity levels that map directly to business impact, so responders can escalate consistently and quickly. This lets the organisation activate the crisis management team at the right threshold without debate, and it aligns response effort with the value at risk rather than with incidental signals such as alert counts or reporter rank.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The seniority of the person who first reported the event to the service desk
Why it's wrong here
Who reports an event says nothing about its impact. A junior analyst may be the first to notice a critical breach, while a senior manager may report a trivial phishing email. Escalation must be driven by the nature and impact of the incident, not by the organisational rank of the reporter.
- ✗
The number of alerts the SIEM generated for the affected host in the last 24 hours
Why it's wrong here
Alert volume measures detection noise, not business consequence. A single low-noise event such as a stolen executive laptop can be far more severe than hundreds of routine malware alerts. Using alert counts as an escalation trigger would produce both false escalations and missed crises, and it is not tied to the impact criteria the plan requires.
- ✗
Whether the affected system is covered by the current cyber insurance policy
Why it's wrong here
Insurance coverage is a financial recovery consideration, not an operational escalation trigger. Systems outside scope can still cause severe business disruption, and coverage questions are typically resolved after containment begins. Basing crisis activation on policy scope would delay response and could leave serious incidents under-managed.
- ✓
The predefined severity level assigned to the incident type and its assessed business impact
Why this is correct
Severity levels are defined in advance against business impact criteria, so the on-call responder can classify an event consistently within minutes and trigger the agreed escalation path. This removes subjective judgement during the most chaotic phase of an incident and ensures the crisis management team is invoked only when the documented thresholds are met.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.