CISM Incident Management Practice Question
An organization has completed its response to a data breach and is conducting a post-incident review. Management wants assurance that lessons learned will actually improve future response capability. Which outcome BEST demonstrates that the post-incident review achieved this objective?
⚠ Common exam trap
The trap here is mistaking communication of findings for remediation of findings, when the review's objective is verified corrective action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The incident response plan is updated with assigned corrective actions, owners, and due dates tracked to closure.
Post-incident reviews only improve capability when findings become tracked corrective actions with named owners and deadlines. This converts analysis into verified changes to plans, controls, and training, and provides management with evidence that gaps have been addressed. Distributing timelines, giving briefings, or archiving reports may support the process but do not by themselves change future response outcomes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A detailed timeline of the incident is distributed to all employees as a training awareness bulletin.
Why it's wrong here
Distributing a timeline raises awareness but does not by itself change response capability. Awareness bulletins rarely alter procedures, roles, or controls. Without assigned corrective actions and verification, the organization may repeat the same gaps. The review's value comes from translating findings into specific, tracked changes to the plan, technology, and training, not from communicating what happened.
- ✗
The final incident report is archived in the document management system for future reference.
Why it's wrong here
Archiving the report satisfies record-keeping but does not drive improvement. A report that is filed and never acted upon leaves root causes and control gaps in place. Effective post-incident reviews require that recommendations be assigned, funded, implemented, and validated, with status reported to management until closure is confirmed.
- ✓
The incident response plan is updated with assigned corrective actions, owners, and due dates tracked to closure.
Why this is correct
The definitive sign that lessons learned will improve capability is that findings are converted into documented corrective actions with accountable owners and deadlines, then tracked to completion. This closes the loop between analysis and change, ensuring gaps in detection, escalation, or containment are remediated. Tracking to closure also gives management measurable assurance rather than a one-time report.
- ✗
The incident response team receives a summary presentation highlighting the attacker's tactics and techniques.
Why it's wrong here
Understanding attacker tradecraft is valuable for detection engineering, but a presentation alone does not modify plans, controls, or responsibilities. Without actions derived from the briefing, the team's response capability remains unchanged. The review must produce concrete changes, such as new detection rules or revised escalation steps, and those changes must be verified as implemented.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.