Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?

⚠ Common exam trap

Candidates often confuse 'revising the IR policy' (a high-level governance document) with 'updating the IR plan and playbooks' (the operational, detailed documentation that directly incorporates lessons learned), leading them to choose the broader, less actionable option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Updating the IR plan and playbooks based on lessons learned

Updating the IR plan and playbooks based on lessons learned is the definitive post-incident activity that directly incorporates findings from the after-action review into the operational documentation. This ensures the plan reflects actual gaps or improvements identified during the incident, making it actionable for future events. Without this update, the plan remains static and fails to evolve with the organization's threat landscape.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Updating the IR plan and playbooks based on lessons learned

    Why this is correct

    Updating the IR plan and playbooks translates lessons learned into revised procedures, contacts and decision criteria, ensuring the next response benefits from the post-incident review. This satisfies the stem's requirement directly, since documentation changes are the mechanism by which findings actually alter future incident handling.

  • ✗

    Sharing indicators of compromise with an ISAC

    Why it's wrong here

    An ISAC shares threat intelligence with peers; it does not feed findings back into this organisation's own response procedures. The post-incident review must amend the plan's playbooks and escalation paths. ISAC sharing is right when the goal is sector-wide early warning of active campaigns against similar targets.

  • ✗

    Revising the IR policy

    Why it's wrong here

    Revising the IR policy addresses governance-level intent, not the operational procedures that failed during the incident. The lessons-learned review targets the plan's playbooks and escalation steps. Policy revision is warranted when mandates or scope change, such as adopting a new regulatory framework or redefining incident severity tiers.

  • ✗

    Conducting a tabletop exercise

    Why it's wrong here

    A tabletop exercise rehearses the plan against hypothetical scenarios; it generates no findings from the actual incident. The post-incident review analyses what occurred and updates the plan accordingly. Tabletop exercises are correct during plan validation or preparation, before an incident occurs.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.