CISM · domain
Incident Management
CISM Domain 3 (Incident Management) covers preparing for, detecting, responding to, and recovering from security incidents while preserving evidence and coordinating business continuity. Questions test judgment on incident classification, escalation to crisis management, forensic evidence handling, root cause analysis, and post-incident review. Expect scenario-based items asking you to select the BEST or FIRST action, often distinguishing technical response from management and governance responsibilities.
Focused practice
Practice Incident Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Incident Management
You must be able to apply the incident response lifecycle to scenarios, prioritize actions, assign crisis team responsibilities, and protect evidence. The single most important thing: identify whether the question tests technical response or management escalation, then choose the action that fits that layer and preserves business and legal interests.
Incident response plan phases: preparation, detection, containment, eradication, recovery, and lessons learned
Evidence handling: chain of custody, forensic imaging, order of volatility, and legal hold procedures
Crisis management team roles, including CEO accountability for business decisions and stakeholder communication
Threat intelligence sharing via trusted frameworks such as ISACs and STIX/TAXII indicators
Watch out for
Common Incident Management exam traps
- ▸Choosing technical containment steps when the question asks for the FIRST management or governance action, such as activating the crisis team or notifying executives.
- ▸Confusing the CEO's crisis role with the CISO's operational role; the CEO decides business impact and communication, not forensic or technical remediation.
- ▸Overlooking evidence preservation requirements, such as capturing volatile data before powering off systems or failing to maintain chain of custody documentation.
Question index
All Incident Management questions (190)
Click any question to see the full explanation, or start a practice session above.
Which of the following is a key reason to have a forensic retainer in place before an incident occurs?
Medium2A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?
Medium3During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?
Medium4Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?
Easy5Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?
Easy6During a major incident, the incident response team determines that the attacker used compromised credentials of a privileged administrator. The team wants to prevent the attacker from re-entering while keeping the business running. Which of the following is the MOST appropriate containment action?
Hard7An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
Easy8What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?
Easy9During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)
Hard10An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?
Medium11As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?
Medium12Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?
Medium13Which of the following incident categories would typically require the involvement of the crisis management team?
Easy14During a major incident, the incident response manager must decide whether to declare a crisis and activate the crisis management team (CMT). Which factor is MOST important in making that decision?
Hard15Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?
Easy16A security operations center (SOC) analyst receives an alert about anomalous outbound traffic from a database server to an unfamiliar external IP address. The analyst confirms the traffic is not authorized and suspects data exfiltration. According to CISM incident management principles, which of the following should the analyst do FIRST?
Hard17A security manager is defining the incident classification scheme for a multinational retailer. Executive leadership wants to know which incidents will trigger a formal crisis management team (CMT) activation. Which criterion should PRIMARILY determine whether an incident is classified as a crisis-level event?
Medium18An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?
Medium19An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?
Hard20A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?
Easy21A financial services firm has activated its crisis management team (CMT) for a significant data breach. The CISO, who is a member of the CMT, is asked to present the technical details of the incident. However, the CMT's primary focus should be on which of the following?
Medium22Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)
Medium23A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?
Medium24Which THREE of the following should be included in an incident communication template?
Medium25Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?
Medium26An organization is developing its incident response plan and wants to ensure that it has the necessary authority and communication channels in place before an incident occurs. Which TWO of the following should be established to enable effective incident response? (Choose two.)
Medium27During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?
Hard28Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?
Medium29What is the PRIMARY reason for having an incident response team roster and contact list readily available?
Easy30During a major incident, the incident response team determines that a compromised server must be rebuilt immediately to restore a critical service. A forensic analyst objects, noting that the server contains evidence relevant to a pending regulatory investigation. How should the incident manager resolve this conflict?
Hard31Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)
Medium32Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?
Medium33An organization's security operations center (SOC) confirms that a production database server is actively exfiltrating customer records to an external IP address. The SOC manager must decide whether to immediately isolate the server from the network. Which factor should PRIMARILY guide this decision?
Medium34An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?
Hard35A security manager is drafting the escalation criteria for the incident response plan. The organisation wants to ensure that incidents are escalated to the crisis management team (CMT) appropriately. Which of the following is the BEST basis for defining when an incident should be escalated to the CMT?
Medium36Which incident severity level requires executive notification and 24/7 response, and has major business impact?
Easy37A security analyst receives an alert from the SIEM indicating that a user account has been added to the domain administrators group outside of the change management window. The analyst confirms the change was not authorized. According to CISM incident management principles, what should the analyst do FIRST?
Easy38A security manager learns that a production database containing customer records was copied to an unauthorized external drive by a contractor. The incident response team has contained the contractor's access. According to CISM best practices, which action should the security manager take NEXT?
Medium39Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?
Medium40Which of the following is the primary reason for conducting a lessons learned meeting after an incident?
Easy41Which of the following is the PRIMARY reason for including communication templates in the incident response plan?
Easy42During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?
Hard43An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?
Medium44Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?
Easy45After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?
Medium46During a major incident, the incident response manager is coordinating containment while the crisis management team (CMT) handles business continuity decisions. A responder proposes immediately wiping and rebuilding an affected server to restore service quickly, but the server contains evidence relevant to a potential legal action. Which of the following is the MOST appropriate action for the incident response manager to take?
Hard47Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)
Hard48After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?
Medium49Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?
Easy50A security operations center (SOC) analyst receives an alert about a possible data exfiltration from a database server. The analyst must determine the incident severity to initiate the appropriate response. Which of the following factors is MOST important in determining the severity level?
Hard51During a live intrusion, the incident response lead must decide how the team will communicate. The attackers are believed to be monitoring the corporate email and collaboration platform. Which of the following is the MOST appropriate action to maintain confidentiality of incident communications?
Hard52Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?
Easy53What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy54Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?
Easy55During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?
Medium56A security manager is drafting the incident classification criteria for a new incident response plan. Executive leadership has asked how the team will decide, in the first few minutes of an event, whether to invoke the crisis management team. Which of the following is the MOST appropriate basis for that initial escalation decision?
Easy57An organisation is defining the criteria its incident response team will use to determine when an incident has been successfully contained and eradication can begin. Which TWO of the following are the MOST appropriate criteria for that decision? (Choose two.)
Hard58An organization's incident response plan delegates authority to the incident commander to make containment decisions during a severe incident. During an active intrusion affecting multiple business units, the incident commander wants to take a system offline that supports a revenue-generating service. Which factor should PRIMARILY guide this containment decision?
Medium59During a security incident, the incident response team needs to preserve volatile evidence. Which of the following should be collected first?
Easy60A multinational retailer's security operations center (SOC) identifies that an attacker has compromised a point-of-sale (POS) system in a European store and is moving laterally toward the payment card processing environment. The incident response manager needs to decide the FIRST action to limit business impact while preserving the ability to investigate. Which action should be taken FIRST?
Medium61During a major incident, the incident response team discovers that the attacker is still active in the environment and is moving laterally. The incident response manager must decide on the immediate course of action. Which of the following should be the PRIMARY consideration when determining whether to isolate affected network segments?
Hard62An organization is developing its incident response plan. The CISO wants to ensure that the plan includes provisions for communicating with external parties during and after an incident. Which of the following should be the PRIMARY consideration when defining external communication procedures?
Medium63An information security manager is drafting the incident escalation criteria for the organization's incident response plan. Executive leadership has asked how the team will decide when an incident must be escalated to the crisis management team rather than handled by the technical response team alone. Which of the following is the MOST appropriate basis for defining these escalation thresholds?
Medium64An organization's incident response plan includes a communication tree that lists internal contacts and external parties. During a moderate incident, the incident manager must notify the party responsible for making binding decisions about public statements and regulatory disclosures. Which role should be contacted for this purpose?
Easy65An organization is conducting a post-incident review after a major phishing-driven breach. The CISO wants to ensure that lessons learned are captured and translated into measurable improvements. Which TWO of the following activities are MOST important to achieve this objective? (Choose two.)
Medium66A retail company's security operations center receives an alert that a point-of-sale terminal is communicating with a known malicious command-and-control domain. The analyst confirms the connection is active. According to incident response best practices, which action should the analyst take FIRST?
Easy67A financial services firm has just contained a breach in which an attacker exfiltrated customer records from a database server. Legal counsel advises the incident manager that the matter will likely result in litigation and regulatory inquiry. Which TWO actions should the incident manager take to preserve the evidentiary value of the affected server? (Choose two.)
Hard68A company's incident response plan defines roles for the incident response team, but during a recent tabletop exercise it became clear that no one had authority to make binding decisions about shutting down production systems. Which of the following should be established to resolve this gap?
Easy69Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?
Hard70An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?
Hard71A multinational organisation suffers a breach affecting customers in several jurisdictions. The incident response manager must coordinate notification obligations while the investigation is still ongoing and facts are incomplete. Which of the following is the MOST appropriate approach?
Hard72A security operations centre (SOC) analyst receives an alert that a production database server is transmitting large volumes of customer data to an external IP address. The analyst confirms the traffic is malicious. According to CISM best practices, which of the following should the analyst do FIRST?
Medium73A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?
Hard74An organization has completed its response to a data breach and is conducting a post-incident review. Management wants assurance that lessons learned will actually improve future response capability. Which outcome BEST demonstrates that the post-incident review achieved this objective?
Medium75During a forensic investigation, the external forensics firm discovers evidence that may indicate criminal activity. The incident manager wants to ensure attorney-client privilege is maintained. What should be done?
Hard76An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?
Medium77Which THREE of the following are typical roles in an incident response team?
Easy78During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?
Medium79A retail company suffers a breach involving payment card data. The incident response manager must decide whether to engage external forensic investigators and outside counsel. Which of the following is the PRIMARY reason to bring in external expertise at this point?
Medium80A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?
Hard81After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?
Medium82A CISO at a healthcare payer is revising the incident response plan after a tabletop exercise exposed confusion about who may commit the organization to public statements and remediation costs during a major breach. The board wants clarity on governance-level decision rights that must exist before the next incident. Which TWO activities should be assigned to the crisis management team rather than to the tactical incident response team? (Choose two.)
Hard83A security manager is reviewing the incident response plan and notices that the plan does not specify how to handle a situation where the incident response team cannot reach the primary incident response manager. What should be done to address this gap?
Hard84An organisation has just completed containment of a significant data breach. The incident response manager is preparing the post-incident review. Which of the following activities BEST ensures that lessons learned translate into lasting improvement of the incident response capability?
Medium85An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)
Easy86An organization is developing its incident response capabilities and wants to ensure that it can effectively detect and respond to security incidents. Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Choose two.)
Medium87Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?
Medium88Which incident category involves unauthorized access to systems or data by an individual within the organization?
Easy89Which incident severity level requires executive notification and a 24/7 response?
Easy90Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?
Hard91A financial services firm's incident response team has contained a credential-stuffing attack that compromised several customer accounts. The CISO asks the incident manager to determine what should happen next before the team stands down. Which action BEST aligns with CISM incident management practices?
Medium92During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?
Medium93In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?
Easy94Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?
Easy95An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?
Medium96Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?
Easy97During a major incident, the incident response team has contained the threat but recovery is taking longer than expected. The business continuity manager reports that the manual workaround in place will fail within four hours due to capacity limits. Which action should the incident manager take FIRST?
Hard98An organization is defining the composition of its incident response team. Which role is PRIMARILY responsible for coordinating communication with the media and the public during a high-profile incident?
Easy99A security manager is drafting the incident response plan and must specify how the organization will communicate with regulators, law enforcement, and the media during a high-severity breach. The chief information security officer (CISO) wants to ensure that all external communications are coordinated, legally defensible, and consistent. Which of the following should the CISO require FIRST to meet this objective?
Medium100During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?
Medium101An organization has experienced a data breach involving customer personally identifiable information (PII). The incident response team has completed containment and eradication. Legal counsel advises that the breach may trigger notification requirements under multiple jurisdictions. Which of the following should the security manager do NEXT to ensure compliance?
Hard102An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?
Hard103An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?
Medium104In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?
Medium105An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?
Medium106Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)
Hard107During a suspected insider data theft, a security manager discovers that an employee copied sensitive pricing files to a personal cloud drive two weeks ago. Legal counsel has not yet decided whether to pursue legal action. The security manager must decide how to treat the forensic copies of the employee's laptop image and cloud access logs. Which action BEST aligns with evidence handling requirements?
Medium108An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?
Medium109During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?
Hard110An organization is reviewing its incident response plan after a prolonged outage caused by a coordinated attack. Management wants to improve the organization's ability to communicate effectively during future incidents. Which TWO of the following should be included in the incident communication plan? (Choose two.)
Medium111An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?
Medium112Which TWO of the following are required components of an incident response programme according to best practices? (Select two.)
Medium113An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?
Hard114An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?
Medium115After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?
Hard116An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?
Medium117A financial services firm has activated its incident response team for a suspected insider data theft. The legal department advises that the matter may become a criminal case. The security manager must decide how to handle the forensic images and analyst notes. Which action BEST supports both the investigation and potential legal proceedings?
Hard118An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?
Easy119A security manager is drafting the incident classification section of the incident response plan. Executives want a documented, repeatable way to rank incidents so that notification and escalation paths are triggered consistently. Which of the following should be the PRIMARY basis for assigning an incident severity level?
Medium120Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?
Easy121During a suspected insider data theft investigation, the incident response team discovers that the suspect's laptop is still powered on and logged in. Legal counsel advises that evidence must be preserved for potential litigation. Which of the following actions should the team take FIRST?
Hard122An organization has just completed containment of a malware outbreak. The incident manager is preparing to transition the incident to the eradication and recovery phase. Which activity should occur FIRST during this transition?
Easy123During a major data breach, the incident response manager needs to determine whether the organization must notify regulators and affected individuals. Which factor is MOST important in making this determination?
Hard124When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?
Medium125An information security manager is building the organization's incident response capability and wants to ensure the team can effectively detect, analyze, and respond to incidents. Which TWO of the following are essential elements that should be established before an incident occurs? (Choose two.)
Medium126An organization's incident response team has contained a malware outbreak, but the attacker's initial access vector remains unknown. Which activity should be performed to reduce the likelihood of recurrence?
Medium127During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?
Hard128An organization operates in multiple jurisdictions and suffers a breach involving personal data of customers in several countries. The incident response manager must coordinate communication with regulators, customers, and internal stakeholders while the technical investigation continues. Which of the following is the MOST important consideration when developing the incident communication strategy?
Hard129An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?
Hard130An organization has experienced a security incident involving unauthorized access to a system containing customer data. The incident response team has contained the incident. According to CISM best practices, which of the following should be performed NEXT?
Easy131Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?
Easy132Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?
Easy133Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?
Hard134After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)
Medium135An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)
Hard136An organization experiences a data breach involving customer personally identifiable information (PII). The incident response team has contained the breach. Which of the following should be the PRIMARY consideration when deciding whether to notify affected customers?
Hard137An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?
Medium138Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?
Hard139Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)
Hard140A company discovers a credential compromise affecting multiple user accounts. According to best practices, what is the first step the incident response team should take?
Hard141An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?
Medium142Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?
Easy143An organization's incident response plan defines containment, eradication, and recovery phases. During a major incident involving a compromised application server, the incident response manager must decide whether to take the server offline immediately or keep it running to observe attacker behavior. Which of the following is the MOST important factor in making this decision?
Medium144During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?
Hard145A security operations center (SOC) analyst receives an alert indicating that a workstation is communicating with a known command-and-control (C2) server. The analyst confirms the traffic is malicious. According to CISM best practices, which action should the analyst take NEXT?
Medium146An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?
Medium147During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?
Medium148An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?
Easy149Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?
Hard150An organization's incident response team is reviewing its post-incident activities after resolving a significant security incident. Management wants to ensure lessons learned are captured and that the response capability improves over time. Which TWO of the following activities are MOST important to include in the post-incident phase? (Choose two.)
Medium151Which TWO of the following are essential components of an incident response programme?
Medium152During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium153During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?
Medium154An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?
Medium155A multinational company experiences a ransomware attack that encrypts critical servers in its European and North American data centers. The incident response team has contained the spread, but restoration will take several days. Executive leadership asks the CISO what should be done to manage the business impact while recovery proceeds. Which of the following is the MOST appropriate immediate action?
Easy156During containment of a confirmed intrusion, the incident response manager must decide whether to immediately rebuild the compromised server or first acquire volatile data. Legal counsel has signalled that litigation is likely. Which of the following is the BEST course of action?
Medium157An organization has just experienced a data breach involving customer personal information. The incident manager is determining the appropriate communication strategy. Which action BEST aligns with CISM incident management practices?
Easy158Which of the following is the PRIMARY reason to include legal counsel in the incident response team?
Medium159Which of the following is the primary purpose of having a pre-established forensic retainer agreement?
Easy160During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?
Medium161During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?
Medium162An organisation is reviewing its incident response capabilities after a near-miss. The CISO wants to ensure the team can effectively detect and respond to future incidents. Which TWO of the following are the MOST important capabilities to establish before an incident occurs? (Choose two.)
Hard163An organization's incident response plan requires that evidence be collected in a forensically sound manner. A responder is about to capture volatile data from a compromised server. Which action BEST preserves the integrity of the evidence?
Medium164Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?
Medium165During a major ransomware incident, the chief information security officer (CISO) must decide whether to pay the ransom to restore encrypted clinical trial data at a pharmaceutical company. The attackers have threatened to publish the data if not paid within 48 hours. Which of the following is the MOST important factor for the CISO to consider when making this business decision?
Hard166Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)
Medium167An organisation has just completed recovery from a significant cybersecurity incident. The CISO wants to ensure the lessons learned are captured and used to improve future response. Which of the following should be performed as part of the post-incident activity?
Easy168Which TWO of the following are essential components of an incident response plan? (Select two.)
Medium169A financial services firm has just contained a malware outbreak that disabled online banking for six hours. The incident commander confirms systems are restored and monitoring is stable. Executive leadership now wants to know what must happen before the incident can be formally closed. Which activity is MOST important to complete prior to closure?
Hard170During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?
Hard171Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?
Medium172Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?
Easy173An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)
Medium174An organization's incident response plan defines communication procedures, but during a recent incident, customers learned about a data breach from media reports before receiving any notification from the company. The information security manager has been asked to address this gap. Which of the following is the MOST effective improvement?
Medium175Which THREE of the following are typical roles in an incident response team? (Select THREE)
Medium176An organization has just experienced a malware outbreak that was contained by isolating affected endpoints. Before restoring the isolated systems to normal operation, the incident response team must decide what activity comes next in the response lifecycle. Which of the following should the team perform NEXT?
Easy177A security manager is reviewing the organization's incident response capabilities. During a tabletop exercise, participants struggled to determine who has authority to shut down a critical production system during a suspected incident. Which action BEST addresses this gap?
Hard178During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?
Hard179A financial services firm has completed containment and eradication of a sophisticated intrusion. The incident response team is now preparing for the post-incident phase. The CISO asks what activity will BEST reduce the likelihood of a similar incident recurring. Which activity should be prioritized?
Hard180During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?
Hard181An organization is reviewing its incident response plan after a tabletop exercise revealed confusion about roles during a major incident. The CISO wants to clarify which activities belong to the incident response team versus the crisis management team. Which TWO of the following activities are PRIMARY responsibilities of the crisis management team during a major incident? (Choose two.)
Medium182What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?
Easy183An organization has just completed its response to a significant security incident. The information security manager is preparing the post-incident review and wants to ensure the effort produces lasting improvement rather than a one-time report. Which of the following activities is MOST important to include in the post-incident review?
Easy184A security manager is drafting the incident response plan and needs to define how the organization will classify and escalate incidents. Executive leadership wants assurance that high-impact incidents reach the right decision-makers quickly. Which of the following should the security manager do FIRST to establish effective incident classification and escalation?
Medium185During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?
Hard186An organization is building its incident response capability and wants to ensure it can effectively detect and respond to incidents. Which TWO of the following are the MOST important foundational elements to establish before an incident occurs? (Choose two.)
Hard187An organization has just contained a malware outbreak on several servers. The incident response manager must decide which activities belong in the eradication phase before restoration begins. Which TWO of the following activities are part of eradication? (Choose two.)
Hard188Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)
Medium189An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)
Medium190Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)
HardOther domains
All CISM exam domains
Frequently asked questions
- What does the Incident Management domain cover on the CISM exam?
- You must be able to apply the incident response lifecycle to scenarios, prioritize actions, assign crisis team responsibilities, and protect evidence. The single most important thing: identify whether the question tests technical response or management escalation, then choose the action that fits that layer and preserves business and legal interests.
- How many questions are in this domain?
- This page lists all 190 Incident Management questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.