Courseiva
Incident Management →hardMultiple Select

CISM Incident Management Practice Question

An organization is building its incident response capability and wants to ensure it can effectively detect and respond to incidents. Which TWO of the following are the MOST important foundational elements to establish before an incident occurs? (Choose two.)

⚠ Common exam trap

The trap here is selecting tangential monitoring or inventory items that sound useful but do not establish the structured response capability CISM requires.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defined incident classification and severity criteria to prioritize response efforts.

The foundational elements for incident response include a documented plan with roles and communication procedures, and defined classification and severity criteria. These enable consistent, prioritized, and coordinated response. Personal social media monitoring, software license inventories, and encryption bans do not provide the structure or detection capability needed before an incident occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Defined incident classification and severity criteria to prioritize response efforts.

    Why this is correct

    Classification and severity criteria allow the organization to triage incidents consistently, allocate resources appropriately, and determine when to escalate to management or activate the crisis management team. CISM treats this as foundational because it ensures that response efforts are proportional to business impact and that critical incidents receive immediate attention, while lower-severity events are handled efficiently.

  • ✓

    A documented incident response plan with defined roles and communication procedures.

    Why this is correct

    A documented incident response plan provides the structure, roles, and communication paths needed to respond consistently and efficiently. CISM emphasizes that without a plan, responses become ad hoc, roles are unclear, and coordination suffers. It is a foundational element because it guides detection, escalation, containment, and recovery, and it should be reviewed and tested regularly to remain effective.

  • ✗

    A complete inventory of every software license purchased by the organization.

    Why it's wrong here

    A software license inventory supports compliance and asset management but is not a foundational incident response element. While asset inventory can help scope incidents, the license list itself does not enable detection or response. CISM foundational elements focus on plans, roles, classification, communication, and testing, so this option does not meet the requirement of the scenario.

  • ✗

    A policy prohibiting any use of encryption within the organization.

    Why it's wrong here

    Prohibiting encryption would weaken security and is not an incident response foundational element. Encryption protects data confidentiality and integrity, and CISM supports its appropriate use. Banning it would increase risk and complicate compliance. This option is clearly wrong because it contradicts security best practices and does not contribute to detecting or responding to incidents.

  • ✗

    A list of all employees' personal social media accounts for monitoring.

    Why it's wrong here

    Monitoring personal social media accounts is not a foundational incident response element and raises privacy and legal concerns. CISM focuses on organizational controls, detection capabilities, and response procedures, not on personal accounts of employees. This option is a distractor because it sounds like monitoring but does not contribute to the structured capability needed to detect and respond to incidents.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.