CISM Incident Management Practice Question
After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The management or governance failure that allowed the process failure.
According to CISM best practices, root cause analysis after a data breach should focus on systemic and organizational factors rather than individuals or financial impacts. Option A is correct because governance failures—such as inadequate security policies, missing oversight, or lack of executive accountability—are root causes that enable process and control breakdowns. Option D is correct because identifying the specific technical vulnerability (e.g., an unpatched CVE, misconfigured firewall rule, or weak authentication mechanism) explains how the breach was technically possible. Option E is correct because the process failure (e.g., absent patch management, ineffective change control, or missing vulnerability scanning) is the underlying reason the vulnerability was allowed to persist. Option B is not a root cause factor; cost is a business impact metric used for post-incident evaluation, not causal analysis. Option C is incorrect because blaming a specific employee who clicked a phishing email addresses a symptom, not the systemic root cause, and CISM emphasizes examining control failures rather than individual blame.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The management or governance failure that allowed the process failure.
Why this is correct
Root cause analysis must extend beyond the immediate technical trigger to the governance layer. Examining the management or governance failure that permitted the process failure to persist identifies systemic accountability gaps, enabling corrective controls that prevent similar PII breaches recurring.
- ✗
The cost of the breach to the organization.
Why it's wrong here
Root cause analysis examines how the breach occurred and which controls failed; financial cost is a business impact metric quantified separately for risk and budget reporting. Cost analysis would be correct when assessing breach impact, not when determining causation.
- ✗
The specific employee who clicked the phishing email.
Why it's wrong here
Root cause analysis targets systemic control failures, process gaps and technical vulnerabilities; singling out the employee who clicked the email assigns blame rather than identifying why the phishing control failed. Individual attribution suits disciplinary investigation, not causal analysis.
- ✓
The technical vulnerability that allowed the breach.
Why this is correct
The technical vulnerability is the direct mechanism that allowed the breach of customer PII. Identifying it precisely, such as an unpatched flaw or misconfiguration, lets the team remediate the exposure and validate that no related weaknesses remain exploitable.
- ✓
The process failure that allowed the vulnerability to exist.
Why this is correct
Examining the process failure that permitted the vulnerability to exist addresses the root cause rather than merely the exploited symptom, satisfying the stem's requirement for causal analysis after a PII breach. CISM distinguishes root cause analysis, which targets underlying control and governance weaknesses, from incident containment or forensic attribution, so this factor belongs among the three.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.