Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)

⚠ Common exam trap

CISM often tests the confusion between general incident response components and insider-threat-specific requirements — candidates may pick ransomware or DDoS procedures because they sound like incident response, but the question specifically asks for insider threat management essentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Procedures for coordinating with human resources and legal departments.

Option B is correct because insider threat incidents require close coordination with human resources and legal departments to handle employee privacy, employment law, evidence handling, and potential disciplinary or legal action properly. Option D is correct because a dedicated insider threat playbook provides specific, pre-defined procedures for detecting, investigating, and responding to malicious or negligent insider activity, which differs from generic incident response steps. Option A is not essential here because ransomware recovery is a separate threat category and does not specifically address insider threat management. Option C is inappropriate and insecure because storing all employee passwords violates least privilege and credential security best practices. Option E is unrelated because DDoS mitigation contacts address external availability attacks, not insider threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A dedicated ransomware recovery procedure.

    Why it's wrong here

    A ransomware recovery procedure addresses external malware encryption, not the insider misuse of legitimate access the plan must cover. It would be correct if the scenario concerned restoring encrypted data after a ransomware outbreak rather than detecting and responding to trusted-user abuse.

  • ✓

    Procedures for coordinating with human resources and legal departments.

    Why this is correct

    Insider cases typically end in disciplinary or criminal proceedings, so the plan must define how IR liaises with HR and legal. This coordination preserves evidence integrity, satisfies employment law obligations and ensures sanctions are lawfully applied rather than handled unilaterally by the security team.

  • ✗

    A list of all employee passwords for investigation purposes.

    Why it's wrong here

    Storing all employee passwords creates a severe credential-compromise and privacy exposure, and insiders could abuse it. It would be tempting as an investigation aid, but it is the correct choice only in no legitimate scenario; credential vaulting with privileged access management replaces this need.

  • ✓

    A playbook specifically for insider threat scenarios.

    Why this is correct

    Insider threats differ from external attacks: the actor holds legitimate access, knows monitoring, and may be a colleague. A dedicated playbook sets insider-specific steps — covert investigation, HR and legal engagement, evidence handling — that a generic malware or perimeter playbook cannot cover adequately.

  • ✗

    Contact information for the DDoS mitigation service provider.

    Why it's wrong here

    DDoS mitigation provider contacts address volumetric network flooding, not insider threat behaviour such as data exfiltration or privilege abuse. It would be correct if the incident response plan needed to restore availability during a distributed denial-of-service attack rather than manage trusted insiders.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.