Isaca
CISM · Question #976
Which of the following should be an information security manager's NEXT step following the detection of a suspected incident?
The correct answer is C. Perform triage on the suspected incident. After detecting a suspected incident, the next step is triage to validate the event, assess scope and severity, and prioritize response actions before escalating or invoking continuity plans.
Submitted by certguy· Apr 18, 2026Information Security Incident Management
Question
Which of the following should be an information security manager's NEXT step following the detection of a suspected incident?
Options
- AReview the sensitivity of detection processes and tools.
- BInvoke the business continuity plan (BCP).
- CPerform triage on the suspected incident.
- DReport the suspected incident to management.
How the community answered
(22 responses)- A9% (2)
- B9% (2)
- C77% (17)
- D5% (1)
Explanation
After detecting a suspected incident, the next step is triage to validate the event, assess scope and severity, and prioritize response actions before escalating or invoking continuity plans.
Topics
#Incident Response#Incident Triage#Incident Management Process
Community Discussion
No community discussion yet for this question.