Courseiva
mediumMultiple Select

CISA Incident Response Plan Practice Question

Which TWO of the following are key elements of an effective incident response plan? (Select exactly 2.)

⚠ Common exam trap

CISA often tests the distinction between core incident response plan elements (escalation, communication) and supporting governance artifacts (post-incident review schedules, asset inventories), tempting candidates to select operational or asset-management items as if they were response essentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A clear escalation path with contact information

Option C is correct because an effective incident response plan must define a clear escalation path with up-to-date contact information so that incidents are routed to the right responders (e.g., Tier 1 → Tier 2 → IR lead → CISO) without delay, which directly reduces mean time to respond. Option E is correct because predefined communication templates for internal and external stakeholders ensure consistent, timely, and legally appropriate messaging during an incident, covering notifications to employees, customers, regulators, and media as required by policies or breach-notification laws. Options A, B, and D do not belong: a post-incident review schedule (A) is a valuable follow-up improvement activity but not a core element of the plan itself, while a software license inventory (B) and hardware serial number list (D) are asset-management records that, although useful for scoping affected systems, are not defining components of an incident response plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A schedule for post-incident reviews

    Why it's wrong here

    Post-incident reviews are a lessons-learned activity performed after closure, so they sit outside the plan's detection, containment, eradication and recovery phases. It is tempting because mature programmes do schedule them, and they would be correct when building a continual improvement process rather than the response plan itself.

  • ✗

    A detailed inventory of software licenses

    Why it's wrong here

    Software licence inventory supports compliance and asset management, giving no capability to detect, contain or recover from an incident. It is tempting because asset registers feed impact assessments, and such an inventory would be correct when preparing for a software audit or licence true-up rather than incident response.

  • ✓

    A clear escalation path with contact information

    Why this is correct

    A clear escalation path with contact information ensures incidents reach the right responders promptly, satisfying the stem's requirement for an effective incident response plan element. Without defined contacts and escalation tiers, detection cannot translate into timely containment.

  • ✗

    A list of all hardware serial numbers

    Why it's wrong here

    Hardware serial numbers serve physical asset tracking and warranty purposes, contributing nothing to incident detection, escalation or containment. It is tempting because responders do need to identify affected hosts, and a serial list would be correct for reconciling equipment during a physical audit or decommissioning exercise.

  • ✓

    Predefined communication templates for internal and external stakeholders

    Why this is correct

    Predefined communication templates let responders notify internal and external stakeholders quickly and consistently during an incident, removing drafting delays and ensuring regulatory and contractual notifications are accurate. This directly supports the plan's coordination and escalation objectives.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.