CISM Incident Management Practice Question
An organization is developing its incident response plan and wants to ensure that it has the necessary authority and communication channels in place before an incident occurs. Which TWO of the following should be established to enable effective incident response? (Choose two.)
⚠ Common exam trap
The trap here is selecting options that sound like security measures but are unrelated to incident response planning, such as monitoring personal social media or setting arbitrary resolution deadlines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A predefined incident response team with clearly defined roles and responsibilities.
Effective incident response requires a predefined team with clear roles and a robust communication plan. These elements ensure that during an incident, responsibilities are understood and information flows to the right stakeholders in a timely manner. Together, they provide the authority and coordination needed to execute the response plan, aligning with CISM's emphasis on preparation and governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all employees' personal social media accounts for monitoring.
Why it's wrong here
Monitoring employees' personal social media accounts is not a standard incident response planning activity and raises privacy and legal concerns. It does not contribute to effective incident response authority or communication. Incident response plans focus on professional communication channels, escalation procedures, and coordination with legal, HR, and communications teams, not personal social media surveillance.
- ✗
A policy requiring all incidents to be resolved within one hour of detection.
Why it's wrong here
A rigid one-hour resolution requirement is unrealistic and may conflict with proper investigation and containment. Incident response timelines should be based on severity and business impact, not arbitrary deadlines. Such a policy could pressure teams to close incidents prematurely, leaving vulnerabilities unaddressed and increasing risk. CISM advocates for severity-based response objectives, not fixed resolution times.
- ✗
A backup of all incident response team members' personal devices.
Why it's wrong here
Backing up personal devices is not a component of incident response planning and may violate privacy policies. Incident response plans focus on organizational assets, systems, and data. Personal device backups do not provide authority, communication channels, or response capabilities. This option is a distractor that confuses personal device management with incident response readiness.
- ✓
A predefined incident response team with clearly defined roles and responsibilities.
Why this is correct
A predefined team with clear roles ensures that during an incident, personnel know exactly what to do, who to report to, and what decisions they are authorized to make. This reduces confusion and delays. CISM emphasizes that incident response planning must include an organizational structure with defined responsibilities, escalation paths, and decision-making authority to enable a coordinated and timely response.
- ✓
A communication plan that includes internal and external stakeholders, with predefined templates and contact information.
Why this is correct
A communication plan ensures that the right people are informed at the right time during an incident. It includes internal escalation contacts, external parties such as regulators, law enforcement, and customers, and predefined message templates. This enables timely, accurate, and legally compliant communication. CISM highlights that communication planning is critical to incident response effectiveness and reputation management.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.