Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?

⚠ Common exam trap

CISM often tests the tension between 'as soon as possible' and 'after enough analysis' — the correct answer is a middle-ground timeframe, not the extreme.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Within 2 weeks of incident resolution

Holding the lessons learned meeting within about two weeks of resolution balances memory freshness with enough time to gather facts and complete preliminary analysis. It is soon enough that details are still accurate but late enough that the team is no longer in firefighting mode. This aligns with common IR frameworks like NIST SP 800-61.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately after containment

    Why it's wrong here

    Holding the meeting immediately after containment occurs before eradication, recovery and full resolution, so the team lacks complete facts about impact and response effectiveness. It tempts because memories are freshest, but the stem specifies the incident is resolved, so the review should follow resolution, not containment.

  • ✗

    Only after the root cause analysis is completed

    Why it's wrong here

    Waiting for root cause analysis delays the meeting until forensic work concludes, losing participants' fresh recollections and letting corrective actions stall. It tempts as rigour, but lessons learned should capture timeline and response gaps promptly; root cause findings can be added later without postponing the session itself.

  • ✓

    Within 2 weeks of incident resolution

    Why this is correct

    Holding the review within two weeks balances memory retention against operational recovery, satisfying the stem's post-resolution timing constraint. Participants still recall technical details and decisions while the incident remains relevant, yet have had sufficient time to decompress. This window also allows evidence gathering and timeline reconstruction before details fade or staff rotate.

  • ✗

    Within 30 days of incident resolution

    Why it's wrong here

    A 30-day window lets details fade and delays corrective actions, weakening the review's value for a high-priority incident. It tempts as a convenient deadline accommodating schedules, but lessons learned should occur soon after resolution while evidence and recollections remain accurate, not at the outer limit.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.