CISM Incident Management Practice Question
An organization's incident response team is reviewing its post-incident activities after resolving a significant security incident. Management wants to ensure lessons learned are captured and that the response capability improves over time. Which TWO of the following activities are MOST important to include in the post-incident phase? (Choose two.)
⚠ Common exam trap
The trap here is equating post-incident work with administrative closure or punitive action, when its real purpose is structured learning and updating response documentation based on validated findings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a structured lessons-learned review with responders and stakeholders to identify gaps and assign improvement actions.
The post-incident phase exists to convert experience into improved capability. A structured lessons-learned review surfaces technical, procedural, and communication gaps and converts them into assigned corrective actions. Updating plans, playbooks, and contact lists based on validated findings ensures those improvements are institutionalized and available for the next event. Together, these activities close the improvement loop and build a more resilient response capability over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately close the incident ticket and archive all communications to reduce administrative overhead.
Why it's wrong here
Closing the ticket and archiving communications prematurely discards the evidence and context needed for analysis, reporting, and potential legal or regulatory obligations. Post-incident activities require retained records to reconstruct timelines and support findings. Reducing administrative overhead is not a valid reason to bypass review; documentation should be preserved according to retention policies, then the incident can be formally closed after improvement actions are assigned.
- ✓
Conduct a structured lessons-learned review with responders and stakeholders to identify gaps and assign improvement actions.
Why this is correct
A structured lessons-learned review captures what worked and what failed while details are fresh, and converting findings into assigned improvement actions ensures the organization actually changes. Without this step, the same weaknesses recur in future incidents. Including both responders and stakeholders broadens perspective, covering technical, process, and communication gaps, and produces prioritized remediation items with owners and due dates.
- ✗
Terminate all personnel who were involved in the incident response to reinforce accountability.
Why it's wrong here
Punitive termination of responders undermines the psychological safety needed for honest lessons-learned reporting and can discourage future disclosure of mistakes. Accountability is addressed through fair review, training, and process improvement rather than blanket dismissal. Blaming individuals also obscures systemic causes, such as missing controls or unclear procedures, which are the real targets of post-incident improvement.
- ✓
Update incident response plans, playbooks, and contact lists based on validated findings from the incident.
Why this is correct
Post-incident findings are only valuable if they are reflected in the plans and playbooks responders will use next time. Updating procedures, escalation contacts, and tooling configurations closes the loop between experience and preparedness. This ensures that improvements identified during review become part of the organization's documented response capability rather than remaining as informal knowledge that erodes over time.
- ✗
Publicly disclose full technical details of the incident to demonstrate transparency to competitors.
Why it's wrong here
Disclosing full technical details to competitors is not a post-incident improvement activity and may expose vulnerabilities, aid attackers, or violate legal and contractual confidentiality obligations. Transparency with regulators, customers, or affected parties is handled through approved communication channels, not indiscriminate public release. The focus of post-incident work is internal learning and capability improvement, not competitive disclosure.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.