CISM Incident Management Practice Question
An organization is conducting a post-incident review after a major phishing-driven breach. The CISO wants to ensure that lessons learned are captured and translated into measurable improvements. Which TWO of the following activities are MOST important to achieve this objective? (Choose two.)
⚠ Common exam trap
The trap here is equating post-incident activity with punishment or spending, when the real objective is documented findings tied to owned, tracked corrective actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assigning corrective actions with owners and due dates based on identified gaps.
Translating lessons learned into improvement requires both documentation and accountability. A formal after-action report records root cause, timeline, and response effectiveness, while assigning corrective actions with owners and due dates ensures findings are acted upon and tracked. Together they create a measurable, repeatable improvement cycle. Punitive measures, evidence deletion, or untargeted budget increases do not achieve this objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disciplining all employees who clicked the phishing link to reinforce security awareness.
Why it's wrong here
Punitive action against employees who clicked a link can discourage prompt reporting and create a culture of fear, which harms future detection. The goal of a post-incident review is to improve controls and awareness, not to assign blame. Disciplining users does not address root causes such as email filtering gaps or lack of multi-factor authentication and may reduce reporting rates.
- ✗
Increasing the security budget for the next fiscal year without linking it to specific findings.
Why it's wrong here
Budget increases without linkage to specific findings are not measurable improvements and may not address the actual gaps. Effective post-incident improvement requires targeted investments tied to identified weaknesses, with metrics to verify effectiveness. A blanket budget increase does not ensure the organization learns from the incident or reduces the likelihood of recurrence.
- ✗
Immediately deleting all affected mailboxes to remove any remaining malicious content.
Why it's wrong here
Deleting affected mailboxes destroys evidence and may impede forensic analysis, legal obligations, and understanding of the attack scope. While removing malicious content is important, it should be done in a controlled manner after evidence is preserved. This action does not contribute to capturing lessons learned and could undermine both the investigation and future improvements.
- ✓
Assigning corrective actions with owners and due dates based on identified gaps.
Why this is correct
Assigning corrective actions with clear owners and due dates converts findings into accountable, trackable improvements. Without ownership and deadlines, lessons learned remain observations rather than changes. This step ensures the post-incident review produces measurable risk reduction and closes the loop on identified weaknesses, which is essential for continuous improvement of the incident response program.
- ✓
Documenting root cause, timeline, and response effectiveness in a formal after-action report.
Why this is correct
A formal after-action report captures the root cause, timeline, and effectiveness of the response, creating an authoritative record for decision-making. It enables the organization to identify control gaps, measure response performance, and assign corrective actions. This documentation is foundational for translating lessons learned into measurable improvements and is a core post-incident activity in CISM guidance.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.