CISM Incident Management Practice Question
An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)
⚠ Common exam trap
CISM often tests the confusion between general incident response components and insider-threat-specific requirements — candidates may pick ransomware or DDoS procedures because they sound like incident response, but the question specifically asks for insider threat management essentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedures for coordinating with human resources and legal departments.
Option B is correct because insider threat incidents require close coordination with human resources and legal departments to handle employee privacy, employment law, evidence handling, and potential disciplinary or legal action properly. Option D is correct because a dedicated insider threat playbook provides specific, pre-defined procedures for detecting, investigating, and responding to malicious or negligent insider activity, which differs from generic incident response steps. Option A is not essential here because ransomware recovery is a separate threat category and does not specifically address insider threat management. Option C is inappropriate and insecure because storing all employee passwords violates least privilege and credential security best practices. Option E is unrelated because DDoS mitigation contacts address external availability attacks, not insider threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A dedicated ransomware recovery procedure.
Why it's wrong here
A ransomware recovery procedure addresses external malware encryption, not the insider misuse of legitimate access the plan must cover. It would be correct if the scenario concerned restoring encrypted data after a ransomware outbreak rather than detecting and responding to trusted-user abuse.
- ✓
Procedures for coordinating with human resources and legal departments.
Why this is correct
Insider cases typically end in disciplinary or criminal proceedings, so the plan must define how IR liaises with HR and legal. This coordination preserves evidence integrity, satisfies employment law obligations and ensures sanctions are lawfully applied rather than handled unilaterally by the security team.
- ✗
A list of all employee passwords for investigation purposes.
Why it's wrong here
Storing all employee passwords creates a severe credential-compromise and privacy exposure, and insiders could abuse it. It would be tempting as an investigation aid, but it is the correct choice only in no legitimate scenario; credential vaulting with privileged access management replaces this need.
- ✓
A playbook specifically for insider threat scenarios.
Why this is correct
Insider threats differ from external attacks: the actor holds legitimate access, knows monitoring, and may be a colleague. A dedicated playbook sets insider-specific steps — covert investigation, HR and legal engagement, evidence handling — that a generic malware or perimeter playbook cannot cover adequately.
- ✗
Contact information for the DDoS mitigation service provider.
Why it's wrong here
DDoS mitigation provider contacts address volumetric network flooding, not insider threat behaviour such as data exfiltration or privilege abuse. It would be correct if the incident response plan needed to restore availability during a distributed denial-of-service attack rather than manage trusted insiders.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.