CISM Incident Management Practice Question
Which of the following incident categories would typically require the involvement of the crisis management team?
⚠ Common exam trap
A common pitfall is to assume that any high-severity technical incident automatically triggers crisis management. However, in the CISM framework, crisis management activation depends on the business impact and the need for executive-level decisions. A quickly mitigated DDoS may be handled by the incident response team alone, whereas a critical ransomware attack affecting core business processes requires crisis management due to the potential for significant financial, legal, and reputational consequences.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A P1 critical-severity ransomware attack encrypting critical systems.
A P1 critical-severity ransomware attack encrypting critical systems requires immediate activation of the crisis management team because it poses an existential threat to business operations, often involving legal, PR, executive, and regulatory stakeholders. The crisis management team handles incidents that exceed the capacity of the incident response team, typically those with high business impact, widespread system compromise, or potential for significant financial/reputational damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A P2 high-severity DDoS attack that has been mitigated within a few hours.
Why it's wrong here
A P2 DDoS attack mitigated within hours is contained by technical response teams under existing incident procedures; crisis management engages when impact escalates beyond operational thresholds to strategic or reputational harm. It tempts because DDoS is high severity, and would be correct if mitigation had failed and services remained down.
- ✗
A P3 medium-severity insider threat involving unauthorized access to a non-critical system.
Why it's wrong here
A P3 insider threat on a non-critical system stays within security and HR investigation channels; crisis management convenes when an incident threatens the organisation's viability, reputation or regulatory standing. It tempts because insider threats carry trust implications, and would be correct if the accessed system were critical or data exfiltration confirmed.
- ✗
A P4 low-severity phishing email reported by a user.
Why it's wrong here
A P4 low-severity phishing report is handled through standard service-desk or security-operations triage, not crisis management, which activates for incidents threatening business continuity or reputation. It tempts because phishing can escalate, and would be correct if the message had led to confirmed widespread compromise.
- ✓
A P1 critical-severity ransomware attack encrypting critical systems.
Why this is correct
A P1 ransomware attack encrypting critical systems threatens business continuity and may involve extortion, regulatory notification and executive decisions beyond IT's authority. This severity and cross-functional impact trigger crisis management team involvement, satisfying the stem's requirement for incidents demanding strategic, organisation-wide response rather than routine technical remediation.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.