Courseiva
Incident Management →easyMultiple Select

CISM Incident Management Practice Question

An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware

A dedicated playbook is warranted for ransomware (A) because it requires a specific, time-critical sequence of containment, isolation of encrypted hosts, identification of the ransomware strain, and recovery from known-good backups to avoid paying the ransom. A dedicated playbook is also warranted for a data breach (C) because it triggers distinct legal, regulatory, and forensic obligations such as breach notification timelines, evidence preservation, and coordination with counsel and regulators. Password expiration (B) is a routine, scheduled identity-management task handled by normal operational procedures, not an incident response playbook. Software update failure (D) is a change/problem management issue resolved through rollback or patch remediation rather than incident response. Phishing simulation (E) is a proactive security-awareness exercise, not an actual incident, so it does not require an incident response playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ransomware

    Why this is correct

    Ransomware demands a dedicated playbook because its encryption, extortion and recovery steps differ fundamentally from other incidents. A predefined sequence covering isolation, backup validation, decryption decisions and ransom policy enables rapid, consistent containment, matching the stem's call for playbooks tailored to distinct incident types.

  • ✗

    Password expiration

    Why it's wrong here

    Password expiration is a scheduled identity lifecycle event, not a security incident; it triggers helpdesk resets, not containment or forensics. Dedicated playbooks belong to incident types such as ransomware or insider threat, where response actions must be rehearsed. Expiration generates predictable, routine tickets that standard service procedures already cover.

  • ✓

    Data breach

    Why this is correct

    Data breaches require a dedicated playbook because notification duties, regulatory deadlines and forensic scoping differ from other incidents. Predefined steps for containment, impact assessment and breach notification ensure legal obligations are met promptly, satisfying the stem's requirement for playbooks covering distinct incident types.

  • ✗

    Software update failure

    Why it's wrong here

    Software update failure is routine patch management, handled through change and release processes rather than security incident playbooks. A dedicated playbook is warranted for incidents such as malware outbreaks or data breaches, which require containment, eradication and notification steps. Update failures lack the adversarial, forensic response actions playbooks exist to standardise.

  • ✗

    Phishing simulation

    Why it's wrong here

    Phishing simulations are authorised security-awareness tests, not incidents, so a response playbook would be triggered by routine training activity rather than an actual compromise. It is tempting because phishing is a genuine incident category, and a playbook would be correct for real reported phishing messages that users have received.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.