Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

A security operations center (SOC) analyst receives an alert about a possible data exfiltration from a database server. The analyst must determine the incident severity to initiate the appropriate response. Which of the following factors is MOST important in determining the severity level?

⚠ Common exam trap

The trap here is equating the volume of data with severity, overlooking that a small breach of highly sensitive data can be far more severe than a large breach of non-sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The potential impact on business operations and regulatory compliance.

Incident severity should be determined by the potential impact on business operations, regulatory compliance, and reputation. CISM stresses that severity classification drives the response level and resource allocation. While data volume, source IP, and detection method are relevant details, they do not define severity. The most important factor is the business impact, as it determines the urgency and scale of the response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The volume of data potentially exfiltrated.

    Why it's wrong here

    Data volume is a factor, but it is not the most important. The criticality of the data and its potential impact on business operations and compliance are more significant. A small amount of highly sensitive data can be more severe than a large amount of public data. This option is a distractor because it focuses on quantity over impact.

  • ✗

    The source IP address of the exfiltration attempt.

    Why it's wrong here

    The source IP address may help identify the attacker but does not determine severity. Severity is about impact, not the origin of the attack. Even if the source is known, the impact could be severe or minor. This option is a distractor because it focuses on technical attribution rather than business impact.

  • ✓

    The potential impact on business operations and regulatory compliance.

    Why this is correct

    This is correct because severity should be based on the potential impact to the business, including financial, operational, legal, and reputational consequences. CISM emphasizes that incident severity must reflect business impact. The volume, source, and detection method are secondary to the actual or potential harm to the organization.

  • ✗

    The method used to detect the exfiltration (e.g., SIEM alert vs. user report).

    Why it's wrong here

    The detection method is not a primary factor in determining severity. Whether the incident was detected by a SIEM or reported by a user, the severity should be based on the impact. This option is a distractor because it confuses detection with impact assessment. The response should be proportional to the impact, not the detection source.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.