Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The incident could cause severe reputational damage

Option A is correct because an incident with the potential to cause severe reputational damage meets the threshold for CMT escalation, since crisis management is invoked when business reputation and stakeholder trust are at stake, not merely for technical containment. Option D is correct because potential for major financial loss or regulatory penalties is a classic CMT escalation trigger, as such consequences require executive-level decision-making, legal counsel, and communications coordination beyond the incident response team's scope. Options B, C, and E are not appropriate standalone criteria: novel malware, third-party origin, and multi-vendor coordination are operational or technical factors that the incident response team can typically handle through normal procedures, and they do not by themselves imply the enterprise-wide business impact that defines a crisis warranting CMT involvement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The incident could cause severe reputational damage

    Why this is correct

    Severe reputational damage meets the CMT escalation threshold because it threatens enterprise-wide viability, not just operational continuity. Crisis management governs strategic and stakeholder response, so incidents with potential brand, regulatory or public-trust consequences require their oversight rather than routine incident handling.

  • ✗

    The incident involves a new type of malware not seen before

    Why it's wrong here

    Novel malware is handled through existing incident response and containment procedures; unfamiliarity alone does not exceed the security team's capability. It tempts because unknown threats feel severe, but CMT escalation criteria hinge on business impact, cross-functional coordination and reputational or regulatory consequences.

  • ✗

    The incident originated from a third-party supplier

    Why it's wrong here

    Origin from a third-party supplier is not itself an escalation trigger; supplier incidents are managed through vendor risk and contract processes. Escalation to the CMT depends on impact severity, scope and business disruption. This criterion would be tempting where supplier due diligence or contractual remediation is required, but that is a procurement concern, not crisis management.

  • ✓

    The incident has potential for major financial loss or regulatory penalties

    Why this is correct

    Major financial loss or regulatory penalties exceed operational incident handling thresholds, demanding executive authority for funding, legal strategy and stakeholder management. This impact-based trigger satisfies the stem's criterion for escalating to the crisis management team.

  • ✗

    The incident requires coordination with multiple external vendors

    Why it's wrong here

    Vendor coordination is routine operational activity managed by the incident response team within existing contracts and contacts. It tempts because multiple parties suggest complexity, but CMT escalation depends on enterprise-wide business impact, strategic decisions or resource authority beyond the incident team's remit.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.