CISM Incident Management Practice Question
An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
A dedicated playbook is warranted for ransomware (A) because it requires a specific, time-critical sequence of containment, isolation of encrypted hosts, identification of the ransomware strain, and recovery from known-good backups to avoid paying the ransom. A dedicated playbook is also warranted for a data breach (C) because it triggers distinct legal, regulatory, and forensic obligations such as breach notification timelines, evidence preservation, and coordination with counsel and regulators. Password expiration (B) is a routine, scheduled identity-management task handled by normal operational procedures, not an incident response playbook. Software update failure (D) is a change/problem management issue resolved through rollback or patch remediation rather than incident response. Phishing simulation (E) is a proactive security-awareness exercise, not an actual incident, so it does not require an incident response playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ransomware
Why this is correct
Ransomware demands a dedicated playbook because its encryption, extortion and recovery steps differ fundamentally from other incidents. A predefined sequence covering isolation, backup validation, decryption decisions and ransom policy enables rapid, consistent containment, matching the stem's call for playbooks tailored to distinct incident types.
- ✗
Password expiration
Why it's wrong here
Password expiration is a scheduled identity lifecycle event, not a security incident; it triggers helpdesk resets, not containment or forensics. Dedicated playbooks belong to incident types such as ransomware or insider threat, where response actions must be rehearsed. Expiration generates predictable, routine tickets that standard service procedures already cover.
- ✓
Data breach
Why this is correct
Data breaches require a dedicated playbook because notification duties, regulatory deadlines and forensic scoping differ from other incidents. Predefined steps for containment, impact assessment and breach notification ensure legal obligations are met promptly, satisfying the stem's requirement for playbooks covering distinct incident types.
- ✗
Software update failure
Why it's wrong here
Software update failure is routine patch management, handled through change and release processes rather than security incident playbooks. A dedicated playbook is warranted for incidents such as malware outbreaks or data breaches, which require containment, eradication and notification steps. Update failures lack the adversarial, forensic response actions playbooks exist to standardise.
- ✗
Phishing simulation
Why it's wrong here
Phishing simulations are authorised security-awareness tests, not incidents, so a response playbook would be triggered by routine training activity rather than an actual compromise. It is tempting because phishing is a genuine incident category, and a playbook would be correct for real reported phishing messages that users have received.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.