nerdexam
Isaca

CISM · Question #939

Which of the following is MOST important for responding effectively to security breaches?

The correct answer is A. Incident classification. Incident classification is the critical first step because it determines the entire response strategy - severity level, who gets notified, what resources are deployed, and how urgently. Without knowing what kind of breach you're dealing with, every subsequent action lacks…

Submitted by stefanr· Apr 18, 2026Information Security Incident Management

Question

Which of the following is MOST important for responding effectively to security breaches?

Options

  • AIncident classification
  • BCommunication plan
  • CChain of custody
  • DLog monitoring

How the community answered

(27 responses)
  • A
    56% (15)
  • B
    11% (3)
  • C
    26% (7)
  • D
    7% (2)

Explanation

Incident classification is the critical first step because it determines the entire response strategy - severity level, who gets notified, what resources are deployed, and how urgently. Without knowing what kind of breach you're dealing with, every subsequent action lacks direction and priority.

Why the others fall short:

  • B. Communication plan - Valuable, but you can only communicate effectively after classification tells you what happened and how serious it is. Communication is downstream of classification.
  • C. Chain of custody - Essential for forensic evidence and legal proceedings, but it's a post-identification concern focused on preserving evidence, not driving the initial response.
  • D. Log monitoring - A detective control used to detect incidents before or during them; it precedes incident response rather than defining how you respond once a breach is confirmed.

Memory tip: Think of the ER triage analogy - paramedics classify patient severity before treatment begins. In incident response, classification is your triage: it tells you whether you're dealing with a scraped knee or a cardiac arrest, and everything else follows from that answer.

Topics

#Incident Response#Incident Classification#Security Breaches#Effective Response

Community Discussion

No community discussion yet for this question.

Full CISM Practice