Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

An organization is developing its incident response capabilities and wants to ensure that it can effectively detect and respond to security incidents. Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse broader security or IT plans, such as asset inventory or disaster recovery, with the core components of an incident response programme.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident response policy and procedures.

The essential components of an incident response programme include an incident response policy and procedures, which provide the framework and steps for handling incidents, and a communication plan, which ensures effective information sharing with stakeholders. These are directly related to the response process and are necessary for a coordinated and effective response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A disaster recovery plan.

    Why it's wrong here

    A disaster recovery plan focuses on restoring IT infrastructure and operations after a major disruption. While related, it is distinct from incident response, which deals with security incidents. Incident response may trigger disaster recovery, but they are separate disciplines. The question asks for components of an incident response programme, not broader business continuity or disaster recovery.

  • ✓

    Incident response policy and procedures.

    Why this is correct

    An incident response policy provides the mandate and framework for the programme, while procedures detail the steps to follow during an incident. These documents ensure consistent and effective response, define roles and responsibilities, and align with business objectives. Without them, response efforts may be ad hoc and inefficient. They are foundational components that must be established before an incident occurs.

  • ✗

    A list of all IT assets and their locations.

    Why it's wrong here

    While an asset inventory is important for many security processes, it is not a core component of the incident response programme itself. Incident response focuses on detecting, containing, eradicating, and recovering from incidents. Asset inventory supports these activities but is typically part of broader IT management. The essential components of incident response are more directly related to the response process.

  • ✗

    A vulnerability management programme.

    Why it's wrong here

    Vulnerability management is a proactive security process that identifies and mitigates vulnerabilities. It is not a component of incident response, although it can reduce the likelihood of incidents. Incident response is reactive, focusing on handling incidents when they occur. Therefore, vulnerability management, while important, is not an essential component of the incident response programme itself.

  • ✓

    A communication plan with internal and external stakeholders.

    Why this is correct

    A communication plan is critical for coordinating with internal teams, management, legal, and external parties such as regulators, customers, and law enforcement. It ensures timely and accurate information sharing, manages reputation, and meets legal obligations. Without it, communication may be chaotic, leading to misinformation and increased impact. This is a key component of incident response preparedness.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.