CISM · domain
Incident Management
Practise Certified Information Security Manager CISM Incident Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Incident Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Incident Management
Incident Management questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Incident Management exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Incident Management questions (146)
Click any question to see the full explanation, or start a practice session above.
Which of the following is a key reason to have a forensic retainer in place before an incident occurs?
Medium2An organization has experienced a DDoS attack that is overwhelming its internet-facing services. The incident response team has implemented mitigations, but services remain degraded. The maximum tolerable downtime (MTD) for the affected services is 4 hours, and 3 hours have passed. Which of the following should the incident manager do NEXT?
Hard3During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?
Medium4Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?
Easy5Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?
Easy6An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
Easy7What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?
Easy8During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)
Hard9An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?
Medium10As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?
Medium11Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?
Medium12Which of the following incident categories would typically require the involvement of the crisis management team?
Easy13Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?
Easy14An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?
Medium15An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?
Hard16Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)
Medium17A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?
Medium18Which THREE of the following should be included in an incident communication template?
Medium19Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?
Medium20During a P1 (critical) security incident, which of the following is the MOST appropriate frequency for providing executive status updates?
Medium21During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?
Hard22Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?
Medium23What is the PRIMARY reason for having an incident response team roster and contact list readily available?
Easy24During a major security incident classified as P1, which of the following is the MOST appropriate communication frequency to the executive team?
Medium25Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)
Medium26Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?
Medium27An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?
Hard28During a P1 (critical) incident, the incident response manager has been providing hourly situation reports (sitreps) to executives. What is the primary reason for involving legal counsel in these communications?
Medium29Which incident severity level requires executive notification and 24/7 response, and has major business impact?
Easy30Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?
Medium31Which of the following is the primary reason for conducting a lessons learned meeting after an incident?
Easy32Which of the following is the PRIMARY reason for including communication templates in the incident response plan?
Easy33During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?
Hard34An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?
Medium35Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?
Easy36After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?
Medium37Which of the following is the PRIMARY purpose of an incident response plan?
Easy38An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is working on containment. Which communication should the incident manager prioritize FIRST?
Hard39Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)
Hard40After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?
Medium41Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?
Easy42Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?
Easy43What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy44During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?
Medium45Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?
Hard46An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?
Hard47A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?
Hard48A security analyst suspects a credential compromise involving an executive's account. The analyst has isolated the system. What should be the NEXT step according to best practices?
Hard49An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?
Medium50Which THREE of the following are typical roles in an incident response team?
Easy51During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?
Medium52A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?
Hard53After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?
Medium54Under the proposed SEC rules for cybersecurity incident disclosure, what is the timeframe for reporting a material cybersecurity incident?
Medium55An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)
Easy56Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?
Medium57Which incident category involves unauthorized access to systems or data by an individual within the organization?
Easy58Which incident severity level requires executive notification and a 24/7 response?
Easy59Which incident severity level requires executive notification and a 24/7 response?
Easy60Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?
Hard61During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?
Medium62In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?
Easy63Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?
Easy64An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?
Medium65Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?
Easy66During a P1 incident involving a ransomware attack, the crisis management team has been activated. The communications lead is drafting an all-staff internal communication. Which of the following should be INCLUDED in this communication?
Hard67During a P1 incident, the incident response manager is preparing an executive sitrep. Which of the following should be included to preserve legal privilege?
Medium68During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?
Medium69An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?
Hard70An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?
Medium71In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?
Medium72Which TWO of the following are incident categories in an incident management programme?
Hard73An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?
Medium74When should an incident response transition to business continuity and disaster recovery (BC/DR) activation?
Medium75After a supply chain attack, the incident response team identifies that a third-party vendor's compromised credentials were used to access the organization's network. Which incident category should this be classified under?
Hard76Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)
Hard77An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?
Medium78During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?
Hard79An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?
Medium80An organization is required to notify regulators of a material cybersecurity incident within 4 business days. Which regulation imposes this requirement?
Hard81An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?
Hard82An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?
Medium83After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?
Hard84An organization maintains evidence handling procedures for incident response. A forensic investigator needs to collect a hard drive from a compromised server. Which of the following is the MOST critical step to ensure admissibility in court?
Hard85An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?
Medium86Which THREE of the following are incident severity levels defined in a typical incident management program? (Select three.)
Medium87An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?
Easy88Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?
Easy89When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?
Medium90Which TWO of the following are key roles on the crisis management team (CMT) for a major cybersecurity incident? (Select two.)
Hard91Which of the following is the FIRST step when engaging an external forensics firm for an incident?
Easy92Following a credential compromise incident, the incident response team is conducting root cause analysis using the 5 Whys technique. The first 'why' reveals that the password was weak. The second 'why' reveals that the password policy allowed simple passwords. What should be the focus of the third 'why'?
Hard93An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?
Hard94Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?
Easy95During a P1 (critical) incident, the incident response manager is coordinating response activities. Who is primarily responsible for activating the crisis management team (CMT)?
Medium96Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy97Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?
Hard98An organization's incident response team is handling a P2 incident involving an insider threat. The team has identified the employee responsible. The communications lead is preparing a notification to affected parties. Which of the following should be included in the notification?
Medium99After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)
Medium100During a DDoS attack classified as P2, what is the EXPECTED response time and notification level?
Medium101An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)
Hard102An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?
Medium103During a DDoS attack, the incident response team is struggling to mitigate the attack. The team decides to engage the organization's ISP and a DDoS mitigation service. Which of the following should be done FIRST?
Medium104Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?
Hard105Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)
Hard106An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?
Medium107Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?
Easy108An organization is conducting a root cause analysis after a data breach. Which of the following sequences BEST aligns with the 5 Whys approach from a CISM perspective?
Medium109During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?
Hard110An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?
Medium111During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?
Medium112An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?
Easy113Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?
Hard114Which TWO of the following are essential components of an incident response programme?
Medium115During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium116After a major incident, the lessons learned meeting is scheduled. According to best practices, when should this meeting typically be held after incident resolution?
Hard117During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?
Medium118An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?
Medium119Which of the following is the PRIMARY reason to include legal counsel in the incident response team?
Medium120Which of the following is the primary purpose of having a pre-established forensic retainer agreement?
Easy121During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?
Medium122During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium123An organization's incident response team is handling a P2 insider threat incident involving unauthorized access to customer data. According to the incident classification, which of the following is the MOST appropriate notification and response timeframe?
Medium124Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?
Medium125Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)
Medium126Which TWO of the following are essential components of an incident response plan? (Select two.)
Medium127An incident response team is handling a P2 (high) incident. According to the incident severity classification, which of the following is the expected response timeframe?
Hard128During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?
Hard129Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?
Medium130Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?
Easy131An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)
Medium132During a P1 incident, the crisis management team (CMT) has been activated. The CEO asks for an hourly sitrep. Which of the following is the MOST appropriate content for the sitrep?
Medium133Which incident severity level requires executive notification and a 24/7 response?
Medium134Which THREE of the following are typical roles in an incident response team? (Select THREE)
Medium135During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?
Hard136During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?
Hard137Which TWO of the following are components of an incident response programme?
Medium138An incident has been declared as P2 (high severity). According to the incident classification, what is the expected response timeframe and notification requirement?
Medium139What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?
Easy140During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?
Hard141An organization has experienced a P2 incident. According to standard incident severity definitions, which response timeframe is typically expected?
Medium142Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)
Medium143An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)
Medium144In the context of incident severity classification, which of the following best describes a P3 (medium) incident?
Easy145An organization has a policy to share indicators of compromise (IoCs) with an Information Sharing and Analysis Center (ISAC). This activity is most closely associated with which phase of incident management?
Medium146Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)
HardOther domains
All CISM exam domains
Frequently asked questions
- What does the Incident Management domain cover on the CISM exam?
- Incident Management questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 146 Incident Management questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.