mediumMultiple Select
CISM Practice Question: An incident response plan should include which…
An incident response plan should include which three key components to ensure effective response? (Choose three.)
⚠ Common exam trap
CISM often tests the distinction between essential process-oriented components (communication, roles, evidence handling) and operational details (specific technical steps or vendor lists) that are too rigid or secondary for a high-level incident response plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Communication procedures for internal and external stakeholders.
Option A is correct because an incident response plan must define communication procedures for internal and external stakeholders, ensuring timely, accurate, and legally appropriate notifications during an incident. Option B is correct because clearly assigned roles and responsibilities of the response team prevent confusion, overlap, and delays by establishing who leads, who investigates, and who escalates. Option E is correct because a method for preserving and handling evidence is essential to maintain forensic integrity, chain of custody, and admissibility for potential legal or disciplinary action. Option C is not appropriate because a plan cannot feasibly contain detailed step-by-step technical instructions for all possible incidents; it should instead reference playbooks or procedures for specific incident types. Option D is not required as a key component because while pre-approved forensic vendors can be useful, they are an optional supporting resource rather than a core element of every incident response plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Communication procedures for internal and external stakeholders.
Why this is correct
Communication procedures ensure timely, accurate notification of internal teams and external parties such as regulators, customers and law enforcement during an incident. This satisfies the stem's requirement for effective response coordination, since escalation paths and stakeholder messaging directly determine how quickly containment and recovery activities proceed.
- ✓
Roles and responsibilities of the response team.
Why this is correct
Defining roles and responsibilities ensures each responder knows their authority and tasks during an incident, eliminating duplicated effort and gaps in coverage. This directly satisfies the stem's requirement for effective response by establishing clear accountability across the Microsoft Entra ID and wider environment, so escalation and containment proceed without confusion.
- ✗
Detailed step-by-step technical instructions for all possible incidents.
Why it's wrong here
Enumerating step-by-step technical instructions for every conceivable incident produces an unmaintainable document that cannot anticipate novel threats; plans instead define roles, escalation paths and communication procedures. It is tempting because runbooks for known, repeatable incidents are genuinely useful, but they belong in playbooks, not as a core plan component.
- ✗
A list of pre-approved vendors for forensic services.
Why it's wrong here
Pre-approved forensic vendors address procurement and legal readiness, not the plan's core response components such as roles, escalation and communication. It is tempting because retaining forensic expertise is valuable during investigations, and vendor lists belong in supporting documentation, but they do not satisfy the three key components the question demands.
- ✓
A method for preserving and handling evidence.
Why this is correct
Preserving and handling evidence maintains forensic integrity and chain of custody, enabling legal admissibility and accurate root-cause analysis during incident response. This satisfies the plan's requirement for structured evidence management, ensuring artefacts are collected, documented and retained correctly so investigations and any subsequent disciplinary or legal proceedings remain defensible.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.