nerdexam
Isaca

CISM · Question #7

An online trading company discovers that a network attack has penetrated the firewall. What should be the information security manager's FIRST response?

The correct answer is A. Evaluate the impact to the business. The information security manager's first response after discovering a network attack that penetrated a firewall should be to evaluate the business impact of the incident.

Submitted by omar99· Apr 18, 2026Information Security Incident Management

Question

An online trading company discovers that a network attack has penetrated the firewall. What should be the information security manager's FIRST response?

Options

  • AEvaluate the impact to the business.
  • BExamine firewall logs to identify the attacker.
  • CNotify the regulatory agency of the incident.
  • DImplement mitigating controls.

How the community answered

(55 responses)
  • A
    82% (45)
  • B
    4% (2)
  • C
    5% (3)
  • D
    9% (5)

Why each option

The information security manager's first response after discovering a network attack that penetrated a firewall should be to evaluate the business impact of the incident.

AEvaluate the impact to the business.Correct

Prioritizing the evaluation of business impact helps determine the severity of the incident, the resources required for response, and informs immediate decisions about containment and recovery, ensuring critical business functions are addressed first. Understanding the business impact dictates the urgency and scale of all subsequent incident response activities.

BExamine firewall logs to identify the attacker.

Examining logs to identify the attacker is part of the investigation phase, which typically follows initial assessment and containment, and is not the absolute first step.

CNotify the regulatory agency of the incident.

Notifying regulatory agencies might be required, but it's usually done after the initial assessment of impact and potential containment, as the scope and details of the incident need to be understood first.

DImplement mitigating controls.

Implementing mitigating controls is part of the containment phase, which occurs after assessing the impact and understanding what exactly needs to be mitigated.

Concept tested: Incident response initial steps (impact assessment)

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf

Topics

#Incident Response#Business Impact Analysis#Incident Management Process#First Response

Community Discussion

No community discussion yet for this question.

Full CISM Practice