Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

During a major data breach, the incident response manager needs to determine whether the organization must notify regulators and affected individuals. Which factor is MOST important in making this determination?

⚠ Common exam trap

The trap here is equating the scale of the technical compromise, such as the number of infected systems, with the legal trigger for notification, when the actual trigger is the type of regulated data exposed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The type of data compromised and applicable legal and regulatory requirements.

Notification decisions are legal and compliance determinations based on what data was exposed and which laws, regulations, or contracts apply. The incident response manager should engage legal counsel and privacy officers early to map the compromised data types to specific reporting obligations and deadlines. Operational metrics such as system count, dwell time, and response cost inform the investigation but do not by themselves establish a duty to notify.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The estimated cost of the incident response effort.

    Why it's wrong here

    Response cost is a business impact consideration that may influence resource allocation and insurance claims but does not establish whether notification is legally required. Regulatory and contractual notification triggers are tied to data types, affected individuals, and jurisdictions, not to how much the response costs. Using cost as the deciding factor could cause the organization to miss mandatory reporting deadlines.

  • ✗

    The number of systems affected by the malware.

    Why it's wrong here

    The count of infected systems is an operational metric that helps scoping and containment but does not by itself determine legal notification obligations. Notification requirements hinge on the type of data involved, the jurisdiction, and the likelihood of harm to individuals. A single compromised server holding regulated personal data can trigger notification, while many infected systems with no regulated data may not.

  • ✗

    The length of time the attacker had access to the environment.

    Why it's wrong here

    Dwell time informs the scope of the investigation and the extent of potential data exposure, but it is not the primary legal trigger for notification. Even a brief compromise of regulated data can require notification, while a long dwell time with no access to protected information may not. The determining factor remains the nature of the data and the applicable legal framework.

  • ✓

    The type of data compromised and applicable legal and regulatory requirements.

    Why this is correct

    Notification obligations are driven by the classification of the data involved and the laws or regulations that apply to the organization, such as privacy statutes, industry rules, or contractual requirements. Determining whether personal, financial, or health information was exposed, and in which jurisdictions, allows legal counsel and compliance to assess mandatory reporting timelines and thresholds accurately.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.