CISM Incident Management Practice Question
An organisation has just completed recovery from a significant cybersecurity incident. The CISO wants to ensure the lessons learned are captured and used to improve future response. Which of the following should be performed as part of the post-incident activity?
⚠ Common exam trap
The trap here is equating incident closure or public communication with lesson learning, when the essential post-incident step is a structured review that produces improvement actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a post-incident review with key stakeholders to identify root cause and improvement actions.
Post-incident activity in CISM is about converting experience into improvement. A structured review with key stakeholders identifies root cause, evaluates the effectiveness of the response, and generates corrective actions that update plans, controls, and training. Closing the ticket, waiting for a fine, or issuing a press release do not build organisational capability. The review ensures the incident response programme evolves and that lessons are documented for future reference and audit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Publish a press release describing the incident and the organisation's response.
Why it's wrong here
Public communication may be required by regulation or reputation management, but it is not the primary post-incident activity for improving response. A press release does not analyse root cause or produce corrective actions. CISM focuses post-incident activity on learning and improvement, with communications handled separately according to legal and public relations guidance. Treating a press release as the main lesson-learned step would leave the underlying weaknesses unaddressed.
- ✓
Conduct a post-incident review with key stakeholders to identify root cause and improvement actions.
Why this is correct
A post-incident review brings together the responders and business stakeholders to examine what happened, why it happened, and what should change. It produces documented improvement actions that feed back into the incident response plan, controls, and training. CISM treats this feedback loop as essential to maturing the incident management capability. Without a structured review, the organisation risks repeating the same failures and cannot demonstrate due diligence to regulators or auditors.
- ✗
Immediately close the incident ticket and return the team to normal duties.
Why it's wrong here
Closing the ticket without analysis discards the opportunity to learn from the event and improve defences. The organisation would lose insight into root cause, control gaps, and response weaknesses. CISM expects post-incident activity to include review and documentation, not just administrative closure. Returning to normal duties is appropriate only after the review is complete and improvement actions are assigned, otherwise the same incident is likely to recur.
- ✗
Update the risk register only if the incident resulted in a regulatory fine.
Why it's wrong here
Every significant incident provides information about risk likelihood and impact, regardless of whether a fine was levied. Waiting for a regulatory penalty before updating the risk register ignores valuable evidence and weakens risk management. CISM expects incidents to inform risk assessment continuously. The post-incident review should trigger risk register updates whenever new threats, vulnerabilities, or control failures are identified, not only when external penalties occur.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.