Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?

⚠ Common exam trap

Candidates often confuse technical severity (e.g., a DDoS causing downtime) with business/regulatory impact, failing to recognize that only incidents with legal or reputational fallout (like a PII breach) necessitate CMT activation, not merely high technical severity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A P1 data breach involving customer personally identifiable information (PII).

A P1 data breach involving customer PII triggers mandatory breach notification laws (e.g., GDPR Article 33, HIPAA Breach Notification Rule) and often requires immediate CMT activation to manage regulatory filings, legal liability, and public relations. The CMT is designed for high-severity incidents with significant business, legal, or reputational consequences, which a P1 breach directly entails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A P1 data breach involving customer personally identifiable information (PII).

    Why this is correct

    A P1 breach of customer PII triggers notification duties under GDPR and similar regimes, plus severe reputational fallout. That combination of regulatory exposure and public trust damage exceeds routine IR handling, so the crisis management team must be activated to coordinate legal, communications and executive response.

  • ✗

    A P2 denial-of-service attack that is quickly mitigated.

    Why it's wrong here

    A quickly mitigated P2 denial-of-service causes minimal regulatory or reputational fallout, so operational response suffices. It tempts because availability incidents feel severe, but crisis management activation is reserved for incidents with enterprise-wide, regulatory or reputational consequences.

  • ✗

    A P4 phishing email reported by a user.

    Why it's wrong here

    A single reported P4 phishing email is routine and handled through standard security operations triage. It tempts because phishing can precede major breaches, but crisis management activation requires confirmed enterprise-wide regulatory or reputational impact, not a low-priority user report.

  • ✗

    A P3 insider threat involving an employee accessing unauthorized files.

    Why it's wrong here

    A P3 insider incident involving unauthorised file access is contained at the operational level and rarely triggers enterprise-wide crisis escalation. It tempts because insider threats carry reputational sensitivity, but CMT activation is reserved for incidents with significant regulatory or public impact.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.