CISM Incident Management Practice Question
An organization's security operations center (SOC) confirms that a production database server is actively exfiltrating customer records to an external IP address. The SOC manager must decide whether to immediately isolate the server from the network. Which factor should PRIMARILY guide this decision?
⚠ Common exam trap
The trap here is assuming that any confirmed exfiltration automatically mandates immediate isolation, ignoring that containment choices must be weighed against business impact and evidence preservation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The potential business impact of taking the server offline versus the value of preserving evidence of the exfiltration channel.
Containment during active exfiltration requires balancing the harm of continued data loss against the harm of disrupting production services and destroying volatile evidence. CISM frames incident response decisions around business impact and evidence integrity, so the decision to isolate must be grounded in that trade-off rather than in threat intelligence reputation, authentication telemetry, or insurance considerations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of failed login attempts recorded on the database server in the preceding 24 hours.
Why it's wrong here
Failed login counts indicate attempted access, not the consequence of isolating a system that is already confirmed to be exfiltrating data. Once exfiltration is verified, authentication telemetry becomes secondary evidence for root cause analysis rather than a driver of the immediate containment decision. Relying on it would misdirect the response away from limiting ongoing data loss and operational disruption.
- ✗
Whether the database server is covered by the organization's cyber insurance policy.
Why it's wrong here
Insurance coverage is a financial recovery consideration that is addressed after containment and during claims handling. It has no bearing on whether to isolate a system that is actively leaking customer records, and waiting on coverage confirmation would prolong the breach. While insurance informs risk transfer strategy, it is not an operational input for the immediate containment choice.
- ✗
Whether the external IP address has been previously reported to a threat intelligence sharing platform.
Why it's wrong here
Threat intelligence reputation is useful context, but it does not determine the containment decision when data is actively leaving the environment. A first-seen or previously unreported IP can still be malicious, and a known-bad IP does not change the business trade-off of isolating a production system. Reputation alone cannot justify delaying or accelerating containment, so it fails as the primary guiding factor here.
- ✓
The potential business impact of taking the server offline versus the value of preserving evidence of the exfiltration channel.
Why this is correct
Isolation decisions during an active exfiltration hinge on balancing containment against operational and evidentiary consequences. Cutting the network link stops data loss but may destroy volatile evidence such as live network connections and in-memory artifacts, and can disrupt critical business services. CISM emphasizes that containment strategy must weigh business impact, legal obligations, and evidence preservation before acting, making this the primary guiding factor.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.