Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

A security manager is reviewing the organization's incident response capabilities. During a tabletop exercise, participants struggled to determine who has authority to shut down a critical production system during a suspected incident. Which action BEST addresses this gap?

⚠ Common exam trap

The trap here is treating a governance gap revealed by an exercise as a technical or training problem, rather than fixing the underlying decision-rights ambiguity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document and communicate clear decision-making authority and escalation paths in the incident response plan

The tabletop exercise revealed that the organization lacks clarity on decision-making authority during incidents. The most effective remedy is to define and communicate who can make high-impact decisions, such as shutting down production, and under what conditions. Documenting escalation paths ensures that responders know when and to whom to escalate. Technical controls and additional certifications do not resolve governance ambiguity, which is the root cause of the observed struggle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require all incident responders to obtain a forensic certification before the next exercise

    Why it's wrong here

    Forensic skills are valuable for evidence handling but do not address who has authority to shut down production. The gap is about decision rights, not technical competence. Certifying responders would not resolve the governance ambiguity revealed in the exercise. CISM focuses on aligning authority and accountability within the incident response structure rather than adding unrelated credentials.

  • ✗

    Increase the frequency of technical vulnerability scans on the critical production system

    Why it's wrong here

    Vulnerability scanning improves detection and hardening but does not resolve ambiguity about decision-making authority during an incident. The exercise revealed a governance and process gap, not a technical control gap. Adding scans would not clarify who can authorize a shutdown or under what conditions. CISM distinguishes technical controls from the governance structures that enable effective incident response.

  • ✗

    Implement an automated tool that shuts down production systems when malware is detected

    Why it's wrong here

    Automated shutdown could cause significant business disruption and may trigger on false positives. More importantly, it does not resolve the underlying question of who holds decision authority and when that authority should be exercised. CISM guidance favors defined human accountability for high-impact decisions, supported by clear criteria, rather than removing human judgment from critical production shutdowns.

  • ✓

    Document and communicate clear decision-making authority and escalation paths in the incident response plan

    Why this is correct

    The exercise exposed uncertainty about who can authorize a disruptive action, which is a governance gap. Clearly documented authority, thresholds, and escalation paths remove ambiguity and speed decision-making during real incidents. CISM emphasizes that incident response plans must define roles, responsibilities, and decision rights in advance. This directly addresses the identified weakness and improves response effectiveness.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.