CISM Incident Management Practice Question
During a major ransomware incident, the chief information security officer (CISO) must decide whether to pay the ransom to restore encrypted clinical trial data at a pharmaceutical company. The attackers have threatened to publish the data if not paid within 48 hours. Which of the following is the MOST important factor for the CISO to consider when making this business decision?
⚠ Common exam trap
The trap here is focusing on the mechanics of payment, such as insurance coverage or a working sample decryptor, rather than on the organization's own ability to recover without paying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whether the organization has a validated, tested backup and recovery capability that can restore the data without paying.
A validated and tested backup and recovery capability is the most important factor because it determines whether the organization can restore operations without paying and without trusting the attacker. It directly supports business continuity and reduces the organization's dependence on criminal actors. Insurance, sample decryptors, and attacker reputation are secondary or unreliable considerations that do not resolve the core recovery and risk question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Whether the organization has a validated, tested backup and recovery capability that can restore the data without paying.
Why this is correct
The existence of validated, tested backups determines whether the organization can recover without funding criminals and without relying on the attackers' promises. This is the most important factor because it directly affects business continuity, data integrity, and the organization's negotiating position. If backups are reliable, payment becomes unnecessary; if they are not, the CISO must weigh residual risk and legal implications. This aligns with CISM's emphasis on resilience and risk-based decision making.
- ✗
Whether the attackers have provided a decryption tool that works on a sample file.
Why it's wrong here
A working sample decryption does not guarantee that all systems or all data will be recoverable, nor does it prevent the attackers from publishing the exfiltrated data or demanding more money. Ransomware operators frequently provide partial or slow decryptors and may re-encrypt or leak data regardless. This factor addresses only a narrow technical proof and ignores the broader business, legal, and reputational risks that should drive the decision.
- ✗
Whether the attackers have a reputation for honoring their promises in previous incidents.
Why it's wrong here
Assessing an attacker's reputation is unreliable and unverifiable; criminal groups often make false claims and may change behavior. Relying on such reputational information introduces significant uncertainty and does not address the organization's own recovery capabilities. It also does not mitigate the legal risks of paying a sanctioned entity or the possibility of future extortion. This is not a sound basis for a major business decision under CISM guidance.
- ✗
Whether the organization has a cyber insurance policy that will reimburse the ransom payment.
Why it's wrong here
Insurance reimbursement is a financial consideration, not the primary decision driver. Even if a policy covers the ransom, paying does not guarantee data recovery or prevent publication, and it may violate sanctions regulations. The CISM focus is on business impact and risk, not on whether the cost is recoverable through insurance. Treating insurance as the deciding factor can lead to a payment that still leaves the organization exposed.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.