Courseiva

CISM · domain

Incident Management

Practise Certified Information Security Manager CISM Incident Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

146 questions34 easy72 medium40 hard

Focused practice

Practice Incident Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Management

Incident Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Incident Management questions (146)

Click any question to see the full explanation, or start a practice session above.

1

Which of the following is a key reason to have a forensic retainer in place before an incident occurs?

Medium
2

An organization has experienced a DDoS attack that is overwhelming its internet-facing services. The incident response team has implemented mitigations, but services remain degraded. The maximum tolerable downtime (MTD) for the affected services is 4 hours, and 3 hours have passed. Which of the following should the incident manager do NEXT?

Hard
3

During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?

Medium
4

Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?

Easy
5

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?

Easy
6

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

Easy
7

What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?

Easy
8

During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)

Hard
9

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?

Medium
10

As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?

Medium
11

Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?

Medium
12

Which of the following incident categories would typically require the involvement of the crisis management team?

Easy
13

Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?

Easy
14

An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?

Medium
15

An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?

Hard
16

Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)

Medium
17

A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?

Medium
18

Which THREE of the following should be included in an incident communication template?

Medium
19

Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?

Medium
20

During a P1 (critical) security incident, which of the following is the MOST appropriate frequency for providing executive status updates?

Medium
21

During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?

Hard
22

Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?

Medium
23

What is the PRIMARY reason for having an incident response team roster and contact list readily available?

Easy
24

During a major security incident classified as P1, which of the following is the MOST appropriate communication frequency to the executive team?

Medium
25

Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)

Medium
26

Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?

Medium
27

An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

Hard
28

During a P1 (critical) incident, the incident response manager has been providing hourly situation reports (sitreps) to executives. What is the primary reason for involving legal counsel in these communications?

Medium
29

Which incident severity level requires executive notification and 24/7 response, and has major business impact?

Easy
30

Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?

Medium
31

Which of the following is the primary reason for conducting a lessons learned meeting after an incident?

Easy
32

Which of the following is the PRIMARY reason for including communication templates in the incident response plan?

Easy
33

During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?

Hard
34

An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?

Medium
35

Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?

Easy
36

After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?

Medium
37

Which of the following is the PRIMARY purpose of an incident response plan?

Easy
38

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is working on containment. Which communication should the incident manager prioritize FIRST?

Hard
39

Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)

Hard
40

After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?

Medium
41

Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?

Easy
42

Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?

Easy
43

What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

Easy
44

During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?

Medium
45

Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?

Hard
46

An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?

Hard
47

A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?

Hard
48

A security analyst suspects a credential compromise involving an executive's account. The analyst has isolated the system. What should be the NEXT step according to best practices?

Hard
49

An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?

Medium
50

Which THREE of the following are typical roles in an incident response team?

Easy
51

During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?

Medium
52

A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?

Hard
53

After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?

Medium
54

Under the proposed SEC rules for cybersecurity incident disclosure, what is the timeframe for reporting a material cybersecurity incident?

Medium
55

An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)

Easy
56

Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?

Medium
57

Which incident category involves unauthorized access to systems or data by an individual within the organization?

Easy
58

Which incident severity level requires executive notification and a 24/7 response?

Easy
59

Which incident severity level requires executive notification and a 24/7 response?

Easy
60

Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?

Hard
61

During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?

Medium
62

In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?

Easy
63

Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?

Easy
64

An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?

Medium
65

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?

Easy
66

During a P1 incident involving a ransomware attack, the crisis management team has been activated. The communications lead is drafting an all-staff internal communication. Which of the following should be INCLUDED in this communication?

Hard
67

During a P1 incident, the incident response manager is preparing an executive sitrep. Which of the following should be included to preserve legal privilege?

Medium
68

During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?

Medium
69

An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?

Hard
70

An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?

Medium
71

In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?

Medium
72

Which TWO of the following are incident categories in an incident management programme?

Hard
73

An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?

Medium
74

When should an incident response transition to business continuity and disaster recovery (BC/DR) activation?

Medium
75

After a supply chain attack, the incident response team identifies that a third-party vendor's compromised credentials were used to access the organization's network. Which incident category should this be classified under?

Hard
76

Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)

Hard
77

An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?

Medium
78

During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?

Hard
79

An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?

Medium
80

An organization is required to notify regulators of a material cybersecurity incident within 4 business days. Which regulation imposes this requirement?

Hard
81

An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?

Hard
82

An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?

Medium
83

After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?

Hard
84

An organization maintains evidence handling procedures for incident response. A forensic investigator needs to collect a hard drive from a compromised server. Which of the following is the MOST critical step to ensure admissibility in court?

Hard
85

An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?

Medium
86

Which THREE of the following are incident severity levels defined in a typical incident management program? (Select three.)

Medium
87

An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?

Easy
88

Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?

Easy
89

When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?

Medium
90

Which TWO of the following are key roles on the crisis management team (CMT) for a major cybersecurity incident? (Select two.)

Hard
91

Which of the following is the FIRST step when engaging an external forensics firm for an incident?

Easy
92

Following a credential compromise incident, the incident response team is conducting root cause analysis using the 5 Whys technique. The first 'why' reveals that the password was weak. The second 'why' reveals that the password policy allowed simple passwords. What should be the focus of the third 'why'?

Hard
93

An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?

Hard
94

Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?

Easy
95

During a P1 (critical) incident, the incident response manager is coordinating response activities. Who is primarily responsible for activating the crisis management team (CMT)?

Medium
96

Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

Easy
97

Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?

Hard
98

An organization's incident response team is handling a P2 incident involving an insider threat. The team has identified the employee responsible. The communications lead is preparing a notification to affected parties. Which of the following should be included in the notification?

Medium
99

After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)

Medium
100

During a DDoS attack classified as P2, what is the EXPECTED response time and notification level?

Medium
101

An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)

Hard
102

An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?

Medium
103

During a DDoS attack, the incident response team is struggling to mitigate the attack. The team decides to engage the organization's ISP and a DDoS mitigation service. Which of the following should be done FIRST?

Medium
104

Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?

Hard
105

Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)

Hard
106

An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?

Medium
107

Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?

Easy
108

An organization is conducting a root cause analysis after a data breach. Which of the following sequences BEST aligns with the 5 Whys approach from a CISM perspective?

Medium
109

During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?

Hard
110

An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?

Medium
111

During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?

Medium
112

An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?

Easy
113

Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?

Hard
114

Which TWO of the following are essential components of an incident response programme?

Medium
115

During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

Medium
116

After a major incident, the lessons learned meeting is scheduled. According to best practices, when should this meeting typically be held after incident resolution?

Hard
117

During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?

Medium
118

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?

Medium
119

Which of the following is the PRIMARY reason to include legal counsel in the incident response team?

Medium
120

Which of the following is the primary purpose of having a pre-established forensic retainer agreement?

Easy
121

During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?

Medium
122

During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

Medium
123

An organization's incident response team is handling a P2 insider threat incident involving unauthorized access to customer data. According to the incident classification, which of the following is the MOST appropriate notification and response timeframe?

Medium
124

Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?

Medium
125

Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)

Medium
126

Which TWO of the following are essential components of an incident response plan? (Select two.)

Medium
127

An incident response team is handling a P2 (high) incident. According to the incident severity classification, which of the following is the expected response timeframe?

Hard
128

During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?

Hard
129

Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?

Medium
130

Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?

Easy
131

An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)

Medium
132

During a P1 incident, the crisis management team (CMT) has been activated. The CEO asks for an hourly sitrep. Which of the following is the MOST appropriate content for the sitrep?

Medium
133

Which incident severity level requires executive notification and a 24/7 response?

Medium
134

Which THREE of the following are typical roles in an incident response team? (Select THREE)

Medium
135

During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?

Hard
136

During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?

Hard
137

Which TWO of the following are components of an incident response programme?

Medium
138

An incident has been declared as P2 (high severity). According to the incident classification, what is the expected response timeframe and notification requirement?

Medium
139

What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?

Easy
140

During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?

Hard
141

An organization has experienced a P2 incident. According to standard incident severity definitions, which response timeframe is typically expected?

Medium
142

Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)

Medium
143

An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)

Medium
144

In the context of incident severity classification, which of the following best describes a P3 (medium) incident?

Easy
145

An organization has a policy to share indicators of compromise (IoCs) with an Information Sharing and Analysis Center (ISAC). This activity is most closely associated with which phase of incident management?

Medium
146

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

Hard

Frequently asked questions

What does the Incident Management domain cover on the CISM exam?
Incident Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 146 Incident Management questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cism ISACA-CISM cism incident management Practice Questions