CISM Incident Management Practice Question
An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedures for isolating affected systems and networks.
Option B is correct because a supply chain incident playbook must include containment procedures that isolate compromised systems and network segments (e.g., disabling switch ports, applying ACLs, or quarantining VLANs) to prevent lateral movement and further propagation from a compromised vendor. Option D is correct because timely, pre-approved communication templates ensure consistent notification of affected partners and customers, satisfying contractual, regulatory, and reputational obligations during a supply chain breach. Option E is correct because contacting legal counsel is essential for assessing liability, regulatory reporting duties, and breach-notification requirements, and this escalation path must be predefined in the playbook. Option A is not appropriate because CISM best practices never prescribe ransom payment procedures; paying ransoms is discouraged and would not be a standard playbook element. Option C does not belong because a list of approved DDoS mitigation vendors is a procurement/vendor-management artifact, not a core incident response playbook element for a supply chain incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A step-by-step guide for paying ransoms to cybercriminals.
Why it's wrong here
Paying ransoms is not a recognised CISM response step; it funds criminal activity, may breach sanctions law, and does not restore operations reliably. It is tempting because ransom payment sometimes appears in real-world ransomware incidents as a last resort, but a playbook should instead cover containment, notification, and recovery procedures.
- ✓
Procedures for isolating affected systems and networks.
Why this is correct
Isolation procedures contain the supply chain compromise by severing affected systems and network segments, preventing lateral spread to internal assets and other partners. This satisfies the playbook requirement for a containment element that limits operational and data exposure during an active incident.
- ✗
A list of approved vendors for DDoS mitigation services.
Why it's wrong here
DDoS is a different incident category; supply chain incidents focus on third-party compromise.
- ✓
Communication templates for notifying affected partners and customers.
Why this is correct
Pre-approved communication templates enable rapid, consistent notification of affected partners and customers, meeting contractual and regulatory obligations while controlling messaging. This satisfies the playbook requirement for a stakeholder communication element during a supply chain incident.
- ✓
Instructions for contacting the organization's legal counsel.
Why this is correct
Instructions for contacting legal counsel ensure timely legal guidance on breach notification duties, regulatory exposure, and privilege preservation. This satisfies the playbook requirement for an escalation element that secures qualified advice before irreversible response decisions are taken.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.