Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

An organization's incident response plan delegates authority to the incident commander to make containment decisions during a severe incident. During an active intrusion affecting multiple business units, the incident commander wants to take a system offline that supports a revenue-generating service. Which factor should PRIMARILY guide this containment decision?

⚠ Common exam trap

The trap here is letting a single consideration such as restoration effort, insurance, or a business owner's preference drive containment, when the governing criterion is balanced business and threat risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The potential business impact of the containment action weighed against the risk of continued attacker activity

Containment decisions require weighing the harm of the action against the harm of inaction. Taking a revenue service offline protects the enterprise from further compromise but disrupts business, while leaving it online preserves revenue but risks escalation. The incident commander uses business impact analysis, threat severity, and organizational risk tolerance to strike the right balance. Restoration difficulty, insurance coverage, and stakeholder preference are secondary inputs, not the primary basis for the decision.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The preference of the business unit leader who owns the revenue-generating service

    Why it's wrong here

    Business unit input is valuable for understanding impact, but deferring to the service owner's preference can subordinate security to short-term revenue concerns. The incident commander holds delegated authority precisely to make objective, risk-based calls that individual stakeholders may resist. Weighing the owner's view as one input is reasonable, yet allowing it to govern the decision would defeat the purpose of centralized incident command and could prolong the intrusion.

  • ✗

    Whether the affected system is covered by the organization's cyber insurance policy

    Why it's wrong here

    Insurance coverage affects financial recovery after an incident but should not dictate real-time containment decisions. Delaying isolation because a system is insured, or acting hastily because it is not, ignores the actual threat to data, customers, and operations. Coverage questions belong with risk management and legal once containment is underway. The primary guide must be the balance of business impact and attacker risk, not the presence of a policy.

  • ✗

    The technical difficulty of restoring the service after it has been taken offline

    Why it's wrong here

    Restoration effort is a relevant input, but it is not the primary driver. A service that is hard to restore might still need immediate isolation if the attacker is exfiltrating regulated data or moving toward critical systems. Conversely, an easily restored service might be left online if impact is minimal. The decision hinges on balancing business harm against attacker risk, with restoration complexity as one supporting factor rather than the governing criterion.

  • ✓

    The potential business impact of the containment action weighed against the risk of continued attacker activity

    Why this is correct

    Containment always involves trade-offs: taking systems offline stops the attacker but may disrupt revenue, while leaving them online preserves service but allows further damage. The incident commander must balance these competing risks using business impact analysis and current threat intelligence. This risk-based judgment, aligned with organizational priorities, is the primary guide. Neither technical feasibility alone nor cost alone captures the full decision, which is fundamentally about acceptable risk.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.