CISM Incident Management Practice Question
An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File a report with the information available and provide updates as the investigation progresses.
Regulatory deadlines must be met even if information is incomplete; disclose what is known and update later.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
File a report with the information available and provide updates as the investigation progresses.
Why this is correct
SEC rules permit filing with incomplete details provided you amend promptly, so filing within the 4-business-day deadline satisfies the reporting constraint while updates cover the ongoing investigation. Waiting for full findings breaches the deadline; silence is not an option.
- ✗
Request an extension from the SEC because the investigation is ongoing.
Why it's wrong here
The SEC rule provides no extension mechanism tied to ongoing investigations; the four-business-day clock is fixed once materiality is determined. It is tempting because investigations genuinely need time, but requesting extensions suits internal escalation timelines, not statutory filing deadlines.
- ✗
Delay reporting until the investigation is complete to ensure accuracy.
Why it's wrong here
Delaying until the investigation concludes exceeds the four-business-day window; the rule requires disclosure once materiality is determined, with later updates if facts change. It is tempting because accuracy matters, but waiting is correct only for incidents not yet assessed as material.
- ✗
Report the incident only if materiality is confirmed at the end of the investigation.
Why it's wrong here
Waiting for confirmed materiality breaches the four-business-day deadline, which runs from determining the incident is material, not from concluding the investigation. It is tempting because premature disclosure risks inaccuracy, but deferring is correct only where no materiality determination has yet been made.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.