nerdexam
Isaca

CISM · Question #976

Which of the following should be an information security manager's NEXT step following the detection of a suspected incident?

The correct answer is C. Perform triage on the suspected incident. After detecting a suspected incident, the next step is triage to validate the event, assess scope and severity, and prioritize response actions before escalating or invoking continuity plans.

Submitted by certguy· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be an information security manager's NEXT step following the detection of a suspected incident?

Options

  • AReview the sensitivity of detection processes and tools.
  • BInvoke the business continuity plan (BCP).
  • CPerform triage on the suspected incident.
  • DReport the suspected incident to management.

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    9% (2)
  • C
    77% (17)
  • D
    5% (1)

Explanation

After detecting a suspected incident, the next step is triage to validate the event, assess scope and severity, and prioritize response actions before escalating or invoking continuity plans.

Topics

#Incident Response#Incident Triage#Incident Management Process

Community Discussion

No community discussion yet for this question.

Full CISM Practice