nerdexam
Isaca

CISM · Question #297

Which of the following is an information security manager's MOST important course of action after receiving information about a new cybersecurity threat?

The correct answer is C. Assess the impact of the new threat on the organization in the event of materialization. After receiving information about a new cybersecurity threat, the most important immediate action is to assess its potential impact on the organization. Not every threat is relevant to every organization - the assessment determines whether the organization is exposed (i.e., has…

Submitted by dimitri_ru· Apr 18, 2026Information Security Risk Management

Question

Which of the following is an information security manager's MOST important course of action after receiving information about a new cybersecurity threat?

Options

  • AReview the enterprise architecture (EA) for vulnerabilities exploited by the threat.
  • BUpdate correlation rules for log monitoring to detect the possible emerging threat.
  • CAssess the impact of the new threat on the organization in the event of materialization.
  • DReport the threat to senior management immediately to enable an informed decision.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    8% (3)
  • C
    72% (28)
  • D
    15% (6)

Explanation

After receiving information about a new cybersecurity threat, the most important immediate action is to assess its potential impact on the organization. Not every threat is relevant to every organization - the assessment determines whether the organization is exposed (i.e., has the vulnerable systems, uses the targeted software, or fits the threat actor's target profile) and what business impact materialization would cause. This assessment informs all subsequent decisions. Reviewing enterprise architecture for vulnerabilities (A) and updating correlation rules (B) are premature without first establishing relevance and severity. Reporting to senior management (D) is important but should come after the security manager has enough information to provide a meaningful briefing - reporting without context adds noise rather than enabling informed decisions.

Topics

#Risk Assessment#Threat Management#Impact Analysis#Security Management Priorities

Community Discussion

No community discussion yet for this question.

Full CISM Practice