CISM Incident Management Practice Question
An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate to the BC/DR team and the authority who can declare a disaster
When MTD is exceeded, the incident escalates to business continuity/disaster recovery activation. The BC/DR decision authority should be notified to declare a disaster and activate recovery plans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify affected customers of the expected delay
Why it's wrong here
Customer notification may be part of the crisis plan but not the immediate next step.
- ✗
Continue containment efforts and hope for a faster recovery
Why it's wrong here
Waiting for a faster recovery leaves the critical process unavailable beyond the MTD with no alternative arrangement, so the business impact continues unmanaged. It tempts because containment is a legitimate incident phase, but here the recovery estimate already exceeds tolerance, requiring escalation to business continuity activation.
- ✓
Escalate to the BC/DR team and the authority who can declare a disaster
Why this is correct
When recovery exceeds the maximum tolerable downtime, the incident manager must escalate to the BC/DR team and the authority empowered to declare a disaster, since only that authority can activate continuity arrangements and commit resources beyond the IR team's remit. Continuing technical recovery alone would breach the MTD.
- ✗
Shut down the affected system to prevent further impact
Why it's wrong here
Shutting the system down removes residual attacker access but also eliminates any chance of restoring the critical process within a tolerable window, so it does not address the MTD breach. It tempts as classic containment, and would be right when spread to other systems is the dominant risk.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.