Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

A security operations center (SOC) analyst receives an alert about anomalous outbound traffic from a database server to an unfamiliar external IP address. The analyst confirms the traffic is not authorized and suspects data exfiltration. According to CISM incident management principles, which of the following should the analyst do FIRST?

⚠ Common exam trap

The trap here is assuming the fastest technical action is best, when unauthorized containment or notification can compromise the investigation and business operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the incident according to the incident response plan and begin documenting actions.

The analyst should escalate according to the incident response plan and begin documenting actions. This ensures proper authorization, coordination, and evidence handling before containment or notification. Premature blocking, shutdown, or external notification can tip off attackers, destroy evidence, or create legal and reputational risk. Following the plan supports a measured, defensible response aligned with CISM incident management principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Escalate the incident according to the incident response plan and begin documenting actions.

    Why this is correct

    Escalating per the incident response plan ensures the right stakeholders are engaged and that actions are coordinated, documented, and authorized. Documentation supports forensic analysis, legal requirements, and post-incident review. This step aligns with CISM principles of following established procedures, maintaining chain of custody, and avoiding unilateral actions that could compromise the investigation or business operations.

  • ✗

    Notify law enforcement and the media before performing any internal investigation.

    Why it's wrong here

    Notifying law enforcement and media before internal validation and scoping can lead to premature disclosure, legal complications, and reputational damage. Law enforcement engagement is often valuable but should follow internal escalation and consultation with legal counsel. The first step is to follow the incident response plan, not to make external notifications based on an unconfirmed suspicion.

  • ✗

    Block the external IP address at the firewall to stop the exfiltration immediately.

    Why it's wrong here

    Blocking the external IP may stop one channel but can tip off the attacker, prompting them to change infrastructure or accelerate damage. It also risks losing visibility into the full scope of the exfiltration and related command-and-control activity. While containment is important, the first step should be to follow the incident response process, which includes validation, scoping, and coordination before taking containment actions.

  • ✗

    Immediately take the database server offline to prevent further data loss.

    Why it's wrong here

    Taking the server offline may stop exfiltration but can destroy volatile evidence, disrupt critical business services, and alert the attacker. It may also prevent the team from understanding the full scope of compromise. Containment decisions should be made after escalation and scoping, with consideration for business impact and evidence preservation, not as an immediate unilateral action by the analyst.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.