mediumMultiple Choice
CISM Practice Question: A security operations center analyst receives an…
A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?
⚠ Common exam trap
Watch out — candidates often confuse 'immediate containment' (a later step in incident response) with 'initial validation,' leading them to choose a disruptive action like blocking or quarantining before confirming the alert is a true positive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review additional logs to confirm
The analyst must first validate the alert by reviewing additional logs (e.g., firewall, proxy, DNS, or endpoint logs) to confirm whether the SIEM alert represents a true positive. Jumping to containment or escalation without confirmation risks unnecessary disruption and false alarms, which violates the incident response principle of 'verify before acting.' The SIEM may have triggered on a benign pattern (e.g., a large file transfer to a trusted cloud service), and only correlated log analysis can establish intent and context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Review additional logs to confirm
Why this is correct
Correlating additional logs lets the analyst validate whether the SIEM alert reflects genuine exfiltration or benign activity, satisfying the need to resolve uncertainty before escalation. This triage step confirms the true-positive status prior to invoking the full incident response process.
- ✗
Escalate to the incident response manager
Why it's wrong here
Escalating to the incident response manager transfers an unvalidated alert upward before any triage establishes whether data exfiltration occurred, bypassing the analyst's own investigation duties. It is tempting because escalation feels safe, and would be correct once triage confirms a genuine incident exceeding the analyst's authority.
- ✗
Immediately block the source IP
Why it's wrong here
Blocking the source IP presumes the alert is genuine and that the source is external and malicious; an unverified alert may reflect benign traffic, and blocking could sever legitimate connectivity. It is tempting as rapid perimeter containment, and would be correct after triage confirms an active external attack.
- ✗
Quarantine the affected system
Why it's wrong here
Quarantining the host acts before triage confirms malicious activity, disrupting a possibly legitimate business system and destroying volatile evidence needed for investigation. It is tempting because isolation contains genuine compromise quickly, and would be correct once the alert is validated as a true positive requiring containment.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.