Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credential compromise playbook

Playbooks are tailored to incident types; credential compromise has its own specific playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data breach playbook

    Why it's wrong here

    A data breach playbook covers unauthorised access to or exfiltration of regulated data, including notification duties. It is tempting because credential compromise can precede a breach, but the stem describes compromised credentials, not confirmed data exposure, so the credential compromise playbook governs.

  • ✗

    Ransomware playbook

    Why it's wrong here

    A ransomware playbook addresses encryption, extortion notes and recovery from backups, not the containment and reset of compromised credentials. It is tempting because ransomware often begins with stolen credentials, but the incident here is the credential compromise itself, so the credential-focused playbook applies.

  • ✓

    Credential compromise playbook

    Why this is correct

    A credential compromise playbook prescribes the exact sequence for this incident type: revoking active sessions and refresh tokens, forcing password resets, and checking for persistence. Generic playbooks lack these credential-specific steps, so they cannot satisfy the stem's requirement to contain the compromised identity before lateral movement.

  • ✗

    Insider threat playbook

    Why it's wrong here

    An insider threat playbook addresses malicious or negligent activity by authorised personnel, including HR and legal coordination. It is tempting because stolen credentials may be used internally, but the stem gives no indication of an insider; the incident is a credential compromise, so that playbook applies.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.