nerdexam
Isaca

CISM · Question #384

Which of the following BEST enables those tasked with analyzing a security breach to understand its impact and report it to the appropriate channels?

The correct answer is A. Security incident classification. Security incident classification provides a structured framework for categorizing incidents by type, severity, and scope, which directly informs analysts about the breach's impact and determines the appropriate reporting channels (e.g., legal, regulatory bodies, executive leaders

Submitted by the_admin· Apr 18, 2026Information Security Incident Management

Question

Which of the following BEST enables those tasked with analyzing a security breach to understand its impact and report it to the appropriate channels?

Options

  • ASecurity incident classification
  • BSecurity breach benchmarking
  • CIncident management training
  • DInformation classification

How the community answered

(25 responses)
  • A
    92% (23)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Security incident classification provides a structured framework for categorizing incidents by type, severity, and scope, which directly informs analysts about the breach's impact and determines the appropriate reporting channels (e.g., legal, regulatory bodies, executive leadership). Benchmarking (B) compares performance against industry peers but does not guide impact analysis or reporting. Incident management training (C) improves response skills generally but does not provide the classification structure needed in the moment. Information classification (D) relates to data sensitivity, not incident categorization. Classification is the mechanism that links an incident's characteristics to the correct response and notification actions.

Topics

#Incident Classification#Breach Analysis#Incident Reporting#Impact Assessment

Community Discussion

No community discussion yet for this question.

Full CISM Practice