mediumMultiple Select
CISA Practice Question: Which TWO of the following are essential…
Which TWO of the following are essential components of an effective incident response plan? (Select exactly 2.)
⚠ Common exam trap
ISACA often tests the distinction between proactive security activities (like vulnerability scanning or vendor lists) and the reactive, operational components of an incident response plan, leading candidates to mistakenly include non-essential items that are important for general IT management but not for immediate incident handling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Clearly defined roles and responsibilities
Option C (Clearly defined roles and responsibilities) is correct because an incident response plan must assign specific duties—such as incident commander, triage lead, and communications officer—so that during a live incident each responder knows exactly who owns containment, eradication, and recovery tasks, preventing duplicated effort or gaps. Option E (Communication and escalation procedures) is correct because the plan must specify internal and external notification paths, escalation thresholds and timeframes, and contact trees (including legal, executive, and regulatory/PR channels) so that incidents are reported and elevated promptly and consistently. The unmarked options do not belong: root cause analysis (A) is a post-incident activity that improves future response but is not an essential structural component of the plan itself, vulnerability scanning schedules (B) belong to vulnerability management rather than incident response, and a hardware vendor contact list (D) is at best a supporting asset inventory detail, not a core component of an effective incident response plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Root cause analysis procedures
Why it's wrong here
Root cause analysis is a post-incident activity performed after containment and recovery, not a component of the response plan itself. It is tempting because it improves future response, and would be correct when defining lessons-learned or continual improvement processes.
- ✗
Detailed vulnerability scanning schedules
Why it's wrong here
Vulnerability scanning schedules belong to vulnerability management, not incident response; they identify weaknesses before incidents occur. It is tempting because scanning supports preventive security, and would be correct when designing a vulnerability management programme rather than an incident response plan.
- ✓
Clearly defined roles and responsibilities
Why this is correct
Defined roles and responsibilities assign specific ownership for detection, containment, eradication and recovery, eliminating ambiguity during high-pressure incidents. Without named accountable parties, response actions stall or duplicate, directly undermining the plan's coordination requirement in the stem.
- ✗
List of all hardware vendors and support contacts
Why it's wrong here
Hardware vendor contacts address procurement and warranty escalation, not containment, eradication or recovery activities. An incident response plan instead needs defined roles, communication paths, escalation criteria and evidence-handling procedures. Vendor lists belong in asset inventories or support agreements, which would be correct for a maintenance or procurement question.
- ✓
Communication and escalation procedures
Why this is correct
Communication and escalation procedures specify whom to notify, at what severity threshold, and through which channels, ensuring stakeholders and management engage promptly. This satisfies the stem's requirement for an effective plan by preventing delayed or missed escalation during incidents.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.