nerdexam
Isaca

CGEIT · Question #62

Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?

The correct answer is C. Response decisions were made without consulting the appropriate authority. The greatest concern for senior management after a high-impact security incident is when response decisions were made without proper authorization, indicating a breakdown in governance and control.

Submitted by kevin_r· Apr 18, 2026Governance of Enterprise IT

Question

Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?

Options

  • ASignificant gaps are present m the incident documentation.
  • BThe incident was not logged in the ticketing system.
  • CResponse decisions were made without consulting the appropriate authority.
  • DResponse efforts had to be outsourced due to insufficient internal resources.

How the community answered

(23 responses)
  • A
    22% (5)
  • B
    4% (1)
  • C
    65% (15)
  • D
    9% (2)

Why each option

The greatest concern for senior management after a high-impact security incident is when response decisions were made without proper authorization, indicating a breakdown in governance and control.

ASignificant gaps are present m the incident documentation.

While significant gaps in incident documentation are problematic for post-incident analysis and improvement, they are less critical than a breakdown in decision-making authority during the active response.

BThe incident was not logged in the ticketing system.

An incident not being logged in the ticketing system indicates a procedural failure, which is a concern for tracking and process adherence, but less severe than incorrect or unauthorized response decisions themselves.

CResponse decisions were made without consulting the appropriate authority.Correct

Unauthorized decision-making during a significant incident implies a failure of established incident response processes, roles, and governance, which can exacerbate impact, incur legal/regulatory issues, and undermine trust.

DResponse efforts had to be outsourced due to insufficient internal resources.

Outsourcing response due to insufficient resources is an operational challenge that can be addressed through planning; it is not as fundamentally concerning as a failure in governance and authorized decision-making during the response.

Concept tested: Incident Management Governance and Authority

Source: https://csrc.nist.gov/pubs/sp/800/61/r2/final

Topics

#Incident Response#Decision Making Authority#IT Governance#Accountability

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice