CISM Incident Management Practice Question
A security manager is drafting the incident classification section of the incident response plan. Executives want a documented, repeatable way to rank incidents so that notification and escalation paths are triggered consistently. Which of the following should be the PRIMARY basis for assigning an incident severity level?
⚠ Common exam trap
The trap here is assuming severity should track technical drama such as attacker sophistication or alert volume rather than the actual business impact of the affected assets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The assessed business impact and the criticality of the affected information assets.
Severity classification must translate technical events into business consequences so that escalation, notification, and resource allocation are consistent and defensible. Basing severity on business impact and asset criticality ensures identical event types can be triaged differently according to what is at stake, and it gives management a repeatable trigger for its involvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of security alerts generated by the detection tooling during the event.
Why it's wrong here
Alert volume reflects sensor sensitivity and tuning, not business harm, so it cannot reliably drive escalation. A noisy but benign scanning campaign can raise hundreds of alerts while a quiet data theft raises a handful. Using alert count as the severity driver would misdirect executive attention and resources, and it ignores CISM's core principle that incident prioritization must be tied to impact on the organization.
- ✓
The assessed business impact and the criticality of the affected information assets.
Why this is correct
Severity exists to align response effort and escalation with the harm an incident can cause, so it must be derived from business impact and asset criticality. This lets the same event type be rated differently depending on which systems and data are touched. It also produces consistent, defensible escalation to management, which is exactly what the incident response plan and governance require.
- ✗
The elapsed time between the first log entry and the moment the analyst opens the ticket.
Why it's wrong here
Dwell time is a useful metric for detection maturity, but it says nothing about the magnitude of harm. A long-dwell incident on an isolated lab network may need no executive escalation, while a five-minute exposure of a payment database demands immediate action. Using elapsed time as the severity basis would misalign response intensity with actual business risk.
- ✗
The technical sophistication of the attacker's tools and malware used in the intrusion.
Why it's wrong here
Attacker sophistication is an intelligence data point, not a business impact measure. A crude phishing kit that exposes regulated customer records harms the organization far more than an elegant exploit against a hardened, low-value test system. Ranking by adversary tradecraft would invert priorities and could delay notification of incidents that carry legal, regulatory, or contractual consequences.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.