CISM Incident Management Practice Question
An information security manager is building the organization's incident response capability and wants to ensure the team can effectively detect, analyze, and respond to incidents. Which TWO of the following are essential elements that should be established before an incident occurs? (Choose two.)
⚠ Common exam trap
The trap here is selecting preventive or promotional activities, such as vulnerability inventories or vendor marketing lists, when the question asks specifically about pre-established incident response capability elements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Documented roles, responsibilities, and contact details for the response team and key internal stakeholders
Effective incident response depends on shared severity definitions and clearly assigned roles with current contacts, because these determine how quickly and consistently the organization triages, escalates, and coordinates. A vulnerability inventory supports prevention rather than response, while assuming incidents stay technical and publishing vendor lists for marketing do not strengthen the capability and can even increase exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Documented roles, responsibilities, and contact details for the response team and key internal stakeholders
Why this is correct
Clear roles and current contact information let the team mobilize quickly and avoid confusion about who decides, who communicates, and who executes. This is foundational to any response capability because incidents rarely occur during business hours with everyone available. Without defined responsibilities, response stalls at the moment speed matters most, increasing impact and cost.
- ✗
A complete inventory of every software vulnerability present across the enterprise
Why it's wrong here
Vulnerability inventory supports preventive risk management, and it can inform response, but it is not an essential element of incident response capability itself. Response requires detection, analysis, containment, and coordination structures. An exhaustive vulnerability list does not tell the team how to classify, escalate, or handle an active incident, so it does not meet the essential-element criterion in this scenario.
- ✓
A defined incident classification and severity scheme agreed with business stakeholders
Why this is correct
A classification and severity scheme gives the team a common language for triage, prioritization, and escalation, and it aligns technical response with business impact. Agreeing it with business stakeholders ensures severity reflects organizational consequence rather than technical curiosity. Without it, response is inconsistent and escalation to management is ad hoc, which undermines the entire programme.
- ✗
A guarantee that no incident will escalate beyond the technical response team
Why it's wrong here
No programme can guarantee that incidents will remain purely technical; major events routinely require executive, legal, and communications involvement. Planning around such an assumption removes escalation paths and crisis management readiness, making the organization less prepared rather than more. This is an unrealistic objective and contradicts sound incident management practice.
- ✗
A published list of the organization's security tool vendors for marketing purposes
Why it's wrong here
Vendor lists can support support and escalation contacts, but publishing them for marketing has no bearing on response effectiveness and may reveal the security stack to adversaries. Incident response readiness depends on classification, roles, procedures, and communications. This option confuses public relations activity with operational capability and does not contribute to detecting or handling incidents.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.