CISM Incident Management Practice Question
An organization has just completed its response to a significant security incident. The information security manager is preparing the post-incident review and wants to ensure the effort produces lasting improvement rather than a one-time report. Which of the following activities is MOST important to include in the post-incident review?
⚠ Common exam trap
The trap here is treating the post-incident review as a documentation or reporting exercise, when its essential output is owned, deadline-driven corrective action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Documenting lessons learned and assigning owners and due dates for corrective actions
The purpose of a post-incident review is continuous improvement, which requires converting observations into tracked corrective actions with accountable owners and deadlines. Distributing technical details, calculating cost, or archiving artifacts may support governance or records management, but none of them ensures the identified weaknesses are actually fixed, so they do not deliver the lasting improvement the manager seeks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Distributing a detailed technical timeline of the attacker's activity to all employees
Why it's wrong here
Broad distribution of attacker tactics can expose sensitive details, aid future adversaries, and overwhelm employees with information they cannot act on. While awareness communication has value, a full technical timeline is not the primary purpose of a post-incident review and may create legal or confidentiality issues. It does not by itself produce corrective action or improvement.
- ✗
Calculating the total cost of the incident to present to the board of directors
Why it's wrong here
Cost quantification is useful for governance and risk discussions, but it is an outcome metric rather than a driver of improvement. Presenting cost alone does not identify what failed, what worked, or what must change. The review's most important product is actionable change, and cost reporting without assigned remediation leaves the organization exposed to recurrence.
- ✓
Documenting lessons learned and assigning owners and due dates for corrective actions
Why this is correct
A post-incident review delivers value only when findings translate into tracked remediation. Capturing lessons learned and converting them into corrective actions with named owners and deadlines closes the loop, ensures accountability, and drives measurable improvement in the incident response plan, controls, and monitoring. Without ownership and deadlines, observations remain recommendations that are rarely implemented.
- ✗
Archiving all incident artifacts and closing the case file in the ticketing system
Why it's wrong here
Retaining artifacts supports evidence and audit needs, and closing the ticket provides administrative closure, but neither improves future response. Archiving is a records-management activity, not a learning or remediation activity. If the review stops at archival, the organization repeats the same mistakes, which is precisely what a post-incident review is intended to prevent.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.