Courseiva
Incident ManagementmediumMultiple ChoiceObjective-mapped

CISM Incident Management Practice Question

An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Credential compromise playbook

Playbooks are tailored to incident types; credential compromise has its own specific playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data breach playbook

    Why it's wrong here

    Data breach may involve exfiltration but not necessarily credential compromise.

  • Ransomware playbook

    Why it's wrong here

    Ransomware involves encryption, not just credential theft.

  • Credential compromise playbook

    Why this is correct

    Each incident type has a dedicated playbook; credential compromise is one.

  • Insider threat playbook

    Why it's wrong here

    Insider threat involves malicious insiders, not necessarily compromised credentials.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.