CISM Incident Management Practice Question
An organization is building its incident response capability and wants to ensure it can effectively detect and respond to incidents. Which TWO of the following are the MOST important foundational elements to establish before an incident occurs? (Choose two.)
⚠ Common exam trap
The trap here is selecting tangential monitoring or inventory items that sound useful but do not establish the structured response capability CISM requires.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defined incident classification and severity criteria to prioritize response efforts.
The foundational elements for incident response include a documented plan with roles and communication procedures, and defined classification and severity criteria. These enable consistent, prioritized, and coordinated response. Personal social media monitoring, software license inventories, and encryption bans do not provide the structure or detection capability needed before an incident occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defined incident classification and severity criteria to prioritize response efforts.
Why this is correct
Classification and severity criteria allow the organization to triage incidents consistently, allocate resources appropriately, and determine when to escalate to management or activate the crisis management team. CISM treats this as foundational because it ensures that response efforts are proportional to business impact and that critical incidents receive immediate attention, while lower-severity events are handled efficiently.
- ✓
A documented incident response plan with defined roles and communication procedures.
Why this is correct
A documented incident response plan provides the structure, roles, and communication paths needed to respond consistently and efficiently. CISM emphasizes that without a plan, responses become ad hoc, roles are unclear, and coordination suffers. It is a foundational element because it guides detection, escalation, containment, and recovery, and it should be reviewed and tested regularly to remain effective.
- ✗
A complete inventory of every software license purchased by the organization.
Why it's wrong here
A software license inventory supports compliance and asset management but is not a foundational incident response element. While asset inventory can help scope incidents, the license list itself does not enable detection or response. CISM foundational elements focus on plans, roles, classification, communication, and testing, so this option does not meet the requirement of the scenario.
- ✗
A policy prohibiting any use of encryption within the organization.
Why it's wrong here
Prohibiting encryption would weaken security and is not an incident response foundational element. Encryption protects data confidentiality and integrity, and CISM supports its appropriate use. Banning it would increase risk and complicate compliance. This option is clearly wrong because it contradicts security best practices and does not contribute to detecting or responding to incidents.
- ✗
A list of all employees' personal social media accounts for monitoring.
Why it's wrong here
Monitoring personal social media accounts is not a foundational incident response element and raises privacy and legal concerns. CISM focuses on organizational controls, detection capabilities, and response procedures, not on personal accounts of employees. This option is a distractor because it sounds like monitoring but does not contribute to the structured capability needed to detect and respond to incidents.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.