Certified Information Security Manager CISM · Free Practice Question Easy

Question 95

What is the purpose of defining severity levels for security incidents?
  • A

    Determine when law enforcement should be contacted.

  • B

    Determine whether outside assistance is required.

  • C

    Identify the executives and team members who should be notified of an unfolding incident.

  • D

    Identify which responders are needed.

Reveal correct answer

Correct answer: C

Explanation

Correct Answer:

"Identify the executives and team members who should be notified of an unfolding incident." is correct. Incident severity helps determine the level of management that needs to be informed of an incident. Severity does not indicate which resources are required.

Incorrect Answers:

"Determine when law enforcement should be contacted." is incorrect because severity level and the need to contact law enforcement are not related.

"Identify which responders are needed." is incorrect because severity level is not a direct indication of what responders are needed; instead, the specific information systems or technologies involved in an incident would indicate which responders are needed.

"Determine whether outside assistance is required." is incorrect because the need for outside assistance is related to skills gaps, not severity levels.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need