Courseiva

CISM Information Security Programme Practice Question

An organization is designing a security operations center (SOC). Which of the following functions is PRIMARILY responsible for analyzing alerts and determining if they represent genuine threats?

⚠ Common exam trap

CISM often tests the distinction between roles: candidates may confuse the Incident Responder (who handles confirmed incidents) with the Security Analyst (who analyzes alerts to determine if they are genuine threats).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Analyst

The Security Analyst (often Tier 1 or Tier 2) is primarily responsible for monitoring alerts, triaging them, and determining whether they represent genuine threats. This role performs the initial analysis and escalates confirmed incidents to incident responders. The SOC Manager oversees operations, the Security Architect designs controls, and the Incident Responder handles confirmed incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SOC Manager

    Why it's wrong here

    The SOC Manager owns staffing, processes, metrics and stakeholder reporting rather than hands-on alert triage; analysing alerts to confirm genuine threats sits with the monitoring analysts. It is tempting because the manager oversees the SOC's detection capability, but oversight and governance differ from the first-line analysis that validates each alert.

  • ✗

    Security Architect

    Why it's wrong here

    Security Architects design controls, reference architectures and security patterns; they do not perform continuous alert triage, which is the monitoring analysts' operational duty. The role is tempting because architects define detection requirements and tooling, but designing the SOC's alerting pipeline is distinct from analysing individual alerts to confirm genuine threats.

  • ✗

    Incident Responder

    Why it's wrong here

    Incident Responders contain and remediate confirmed incidents; triaging alerts to establish whether they are genuine threats belongs to the Tier 1 analyst or triage function, which performs initial validation before escalation. The role is tempting because responders do investigate incidents, but they engage after triage has already determined an alert is a real threat.

  • ✓

    Security Analyst

    Why this is correct

    Security analysts perform tier-one triage, correlating alerts from SIEM and other monitoring tools and investigating whether activity constitutes a genuine threat. This alert analysis and escalation decision-making is their primary function, distinct from engineering, monitoring tooling ownership or management oversight.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.