CISSP Security Operations Practice Question
A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?
⚠ Common exam trap
CISSP often tests whether candidates can distinguish actual incident categories from routine IT processes or preparedness activities, so they mistakenly select change requests or BC exercises as incident types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denial of Service (DoS)
Option B, Denial of Service (DoS), is a valid incident category because standard IR frameworks such as NIST SP 800-61 and SANS categorize attacks that degrade or block availability of systems and networks (e.g., volumetric floods, SYN floods, application-layer exhaustion) as a distinct incident type requiring specific detection and containment playbooks. Option D, Insider threat, is also a valid category because incidents involving authorized users—whether malicious, negligent, or compromised—such as data exfiltration, privilege abuse, or credential misuse are treated as a separate class due to their unique investigative and legal handling needs. The remaining options are not incident categories: A, Change request, is an ITIL change-management artifact, not an incident type; C, Patch management failure, is a vulnerability or configuration management issue that may contribute to an incident but is not itself a standard IR category; and E, Business continuity exercise, is a planned testing activity, not a security incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change request
Why it's wrong here
A change request is a formal proposal to modify an IT system, service, or configuration, falling under the purview of change management. It represents a planned and controlled process, not an unexpected or adverse security event that would constitute an incident. Incidents, by definition, are deviations from normal operations that threaten security, whereas change requests are part of normal, managed operations.
- ✓
Denial of Service (DoS)
Why this is correct
Denial of Service (DoS) is a critical incident category because it directly impacts the availability of systems and services, often rendering them inaccessible to legitimate users. This type of attack involves overwhelming a target with traffic or requests, consuming resources, and preventing normal operation. Such an event requires immediate incident response to restore service and mitigate ongoing impact.
- ✗
Patch management failure
Why it's wrong here
Patch management failure describes a deficiency in an organization's security controls or processes, specifically the inability to apply necessary security updates. While this failure creates a significant vulnerability that can *lead* to an incident, it is not an incident itself. It represents a pre-incident condition or a control gap that increases risk, rather than an active security breach or adverse event.
- ✓
Insider threat
Why this is correct
Insider threat is a distinct and critical incident category that describes security events originating from individuals within an organization who have authorized access to systems or data. This category encompasses malicious activities such as data exfiltration, sabotage, or unauthorized access, leveraging trusted positions. Recognizing an incident as an insider threat guides specific response and forensic strategies due to the unique access and knowledge of the perpetrator.
- ✗
Business continuity exercise
Why it's wrong here
A business continuity exercise is a planned simulation designed to test an organization's ability to maintain essential functions during and after a disruption. These exercises are proactive preparedness activities, not actual security incidents or adverse events. While they might simulate incident scenarios, the exercise itself is a controlled test, distinct from a real-world incident that triggers an unplanned, reactive response.
Go deeper
Related to this question
Learn chapter
Security Assessment and Testing
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.