easyMultiple ChoiceObjective-mapped
First Action on Data Exfiltration Alert: Verify
An analyst receives an alert indicating a potential data exfiltration. The alert shows a host IP address 10.10.50.200 sending large amounts of data to an external IP address 203.0.113.5 over port 443. What should the analyst do FIRST?
Quick Answer
The correct first action is to verify the alert by checking logs and network traffic. This step is critical because alerts can be triggered by legitimate high-volume activity, such as a scheduled backup to a cloud service or a large software update over port 443, which is standard HTTPS traffic. Prematurely blocking the IP or isolating the host without validation risks disrupting business operations and destroying potential forensic evidence. On the Certified Information Security Manager CISM exam, this scenario tests your grasp of the incident response lifecycle, specifically the “detection and analysis” phase, where validation precedes containment. A common trap is jumping to containment or eradication, but the exam emphasizes that an unverified alert is just noise. Remember the mnemonic “VICE” for the first steps: Verify, Isolate, Contain, Eradicate—always start with Verify.
⚠ Common exam trap
The trap here is that candidates often jump to containment (isolate or block) without first verifying the alert, confusing the urgency of a potential exfiltration with the disciplined step of validation required by the NIST SP 800-61 incident response lifecycle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the alert by checking logs and network traffic
The first step in incident response is to validate the alert. The analyst must verify that the traffic is indeed anomalous and not legitimate (e.g., a large backup or software update) by examining logs and packet captures. Premature action without verification could disrupt business operations or destroy forensic evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the external IP address immediately
Why it's wrong here
Blocking prematurely may disrupt legitimate traffic without confirmation.
- ✗
Escalate to the incident response team
Why it's wrong here
Escalation is appropriate after initial triage and verification.
- ✓
Verify the alert by checking logs and network traffic
Why this is correct
Verification ensures the incident is real before further action.
- ✗
Isolate the host from the network
Why it's wrong here
Isolation is a containment step that should follow verification.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security operations center analyst receives an alert from the SIEM indicating a possible data exfiltration. The analyst is unsure if it is a true positive. What is the MOST appropriate action?
medium- ✓ A.Review additional logs to confirm
- B.Escalate to the incident response manager
- C.Immediately block the source IP
- D.Quarantine the affected system
Why A: The analyst must first validate the alert by reviewing additional logs (e.g., firewall, proxy, DNS, or endpoint logs) to confirm whether the SIEM alert represents a true positive. Jumping to containment or escalation without confirmation risks unnecessary disruption and false alarms, which violates the incident response principle of 'verify before acting.' The SIEM may have triggered on a benign pattern (e.g., a large file transfer to a trusted cloud service), and only correlated log analysis can establish intent and context.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.