CISM Incident Management Practice Question
Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?
⚠ Common exam trap
ISACA CISM often tests the distinction between the incident category (who or what caused it) and the incident type or outcome, leading candidates to confuse 'insider threat' with 'data breach' because a data breach can be caused by an insider, but the question asks for the category that involves the employee's action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insider threat
An insider threat is the correct category because it specifically involves harm caused by individuals within the organization, whether through malicious intent (e.g., data exfiltration, sabotage) or accidental actions (e.g., misconfiguration, phishing click). This aligns with the CISM definition of insider threats as incidents originating from employees, contractors, or trusted partners who have authorized access to information systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data breach
Why it's wrong here
A data breach is the outcome of unauthorised access or disclosure, not the category describing an employee causing harm. It fits scenarios where confidential records are exposed or exfiltrated; the stem asks about insider-caused damage, which is the insider threat category.
- ✗
DDoS
Why it's wrong here
DDoS is an external availability attack flooding services from distributed sources, not harm originating from an employee. It is the correct category when traffic volume from many hosts overwhelms a service; the stem instead describes insider-caused damage, whether intentional or accidental.
- ✗
Ransomware
Why it's wrong here
Ransomware is malware encrypting data for extortion, typically delivered by external actors, not a category defined by employee intent or accident. It is correct when files are encrypted and a ransom demanded; the stem describes harm caused by an employee, which is insider threat.
- ✓
Insider threat
Why this is correct
Insider threats uniquely cover harm caused by employees, whether malicious or accidental, matching the stem's requirement for internal actors. Unlike external categories such as hacktivists or nation-states, this classification hinges on the actor's authorised access and trusted position within the organisation, satisfying the intent and origin constraints.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.