Courseiva
mediumMultiple Choice

CISM Practice Question: A security operations center analyst receives an…

A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?

⚠ Common exam trap

Watch out — candidates often confuse 'immediate containment' (a later step in incident response) with 'initial validation,' leading them to choose a disruptive action like blocking or quarantining before confirming the alert is a true positive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review additional logs to confirm

The analyst must first validate the alert by reviewing additional logs (e.g., firewall, proxy, DNS, or endpoint logs) to confirm whether the SIEM alert represents a true positive. Jumping to containment or escalation without confirmation risks unnecessary disruption and false alarms, which violates the incident response principle of 'verify before acting.' The SIEM may have triggered on a benign pattern (e.g., a large file transfer to a trusted cloud service), and only correlated log analysis can establish intent and context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Review additional logs to confirm

    Why this is correct

    Correlating additional logs lets the analyst validate whether the SIEM alert reflects genuine exfiltration or benign activity, satisfying the need to resolve uncertainty before escalation. This triage step confirms the true-positive status prior to invoking the full incident response process.

  • ✗

    Escalate to the incident response manager

    Why it's wrong here

    Escalating to the incident response manager transfers an unvalidated alert upward before any triage establishes whether data exfiltration occurred, bypassing the analyst's own investigation duties. It is tempting because escalation feels safe, and would be correct once triage confirms a genuine incident exceeding the analyst's authority.

  • ✗

    Immediately block the source IP

    Why it's wrong here

    Blocking the source IP presumes the alert is genuine and that the source is external and malicious; an unverified alert may reflect benign traffic, and blocking could sever legitimate connectivity. It is tempting as rapid perimeter containment, and would be correct after triage confirms an active external attack.

  • ✗

    Quarantine the affected system

    Why it's wrong here

    Quarantining the host acts before triage confirms malicious activity, disrupting a possibly legitimate business system and destroying volatile evidence needed for investigation. It is tempting because isolation contains genuine compromise quickly, and would be correct once the alert is validated as a true positive requiring containment.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.