CISM Incident Management Practice Question
An organisation has just completed containment of a significant data breach. The incident response manager is preparing the post-incident review. Which of the following activities BEST ensures that lessons learned translate into lasting improvement of the incident response capability?
⚠ Common exam trap
The trap here is equating communication of lessons learned, such as distributing a report, with actually implementing and verifying the resulting improvements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assigning each corrective action to an accountable owner with a due date and tracking it to closure
The purpose of a post-incident review is to convert findings into verified improvements. Assigning each corrective action to a named owner with a deadline and tracking it to closure provides the accountability and visibility that turn recommendations into real capability gains, and it produces evidence that management acted on the lessons identified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Circulating the final incident report to all staff so everyone is aware of what happened
Why it's wrong here
Broad distribution raises awareness but does not change capability. Without assigned owners, deadlines, and verification, the findings remain informational. Reports containing sensitive details may also create unnecessary exposure. Awareness is a by-product of a lessons-learned process, not the mechanism that ensures corrective actions are actually implemented and validated.
- ✗
Updating the risk register to reflect the incident and then archiving the incident documentation
Why it's wrong here
Updating the risk register records the event but does not remediate the underlying weaknesses. Archiving the documentation immediately also removes the working reference needed to verify that fixes were made. Risk registration is a governance step that should accompany corrective actions, not replace them, and premature archiving undermines both auditability and follow-through.
- ✓
Assigning each corrective action to an accountable owner with a due date and tracking it to closure
Why this is correct
Lasting improvement requires converting findings into owned, time-bound actions that are tracked until verified complete. This creates accountability and makes gaps visible to management. Tracking to closure also provides evidence for auditors and regulators that the organisation acted on the incident rather than merely documenting it, which is the essence of an effective lessons-learned process.
- ✗
Conducting a tabletop exercise on the same scenario within the following week
Why it's wrong here
A tabletop exercise can validate improvements, but running one before corrective actions are defined and implemented simply re-tests the same weaknesses. It also consumes responder time immediately after a taxing incident. Exercises are valuable as verification after remediation, not as a substitute for the disciplined assignment and tracking of corrective actions.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.