CISM · Question #716
An information security manager is alerted to multiple security incidents across different business units, with unauthorized access to sensitive data and potential data exfiltration from critical…
The correct answer is B. Prioritize the incidents based on data classification standards. Prioritizing by data classification standards (B) is the best first action because classification frameworks directly determine the sensitivity and business impact of compromised data, which is the foundation for rational incident prioritization - you cannot effectively triage…
Question
An information security manager is alerted to multiple security incidents across different business units, with unauthorized access to sensitive data and potential data exfiltration from critical systems. Which of the following is the BEST course of action to appropriately classify and prioritize these incidents?
Options
- AAssemble the incident response team to evaluate the incidents.
- BPrioritize the incidents based on data classification standards.
- CInitiate the crisis communication plan to notify stakeholders of the incidents.
- DEngage external incident response consultants to conduct an independent investigation.
How the community answered
(66 responses)- A5% (3)
- B83% (55)
- C2% (1)
- D11% (7)
Explanation
Prioritizing by data classification standards (B) is the best first action because classification frameworks directly determine the sensitivity and business impact of compromised data, which is the foundation for rational incident prioritization - you cannot effectively triage multiple incidents without knowing the value of what was exposed.
- A is wrong because assembling the IR team is a process step, not a classification or prioritization mechanism; the team still needs criteria (like data classification) to rank incidents once assembled.
- C is wrong because stakeholder notification is a downstream action that should follow assessment and prioritization, not precede it - communicating before you understand severity risks misinformation and panic.
- D is wrong because engaging external consultants adds delay and cost without solving the immediate need to classify and rank the incidents; this may be appropriate later for investigation, not triage.
Memory tip: Think of the incident lifecycle as "Classify → Prioritize → Respond → Communicate." Option B maps to the earliest and most foundational step - you must know what was affected before you can decide how urgently to act or who to tell.
Topics
Community Discussion
No community discussion yet for this question.