Courseiva

CCNA Incident Management Questions

75 of 190 questions · Page 1/3 · Incident Management · Answers revealed

1
MCQmedium

Which of the following is a key reason to have a forensic retainer in place before an incident occurs?

A.To avoid the need for a chain of custody
B.To ensure the firm understands the organization's IT environment
C.To guarantee lower costs
D.To reduce the time needed to engage the firm when an incident occurs
AnswerD

A retainer pre-negotiates rates, scope and contact details with the forensic firm, so engagement begins immediately when an incident strikes rather than after procurement and contracting delays. This directly reduces the time to engage, preserving volatile evidence.

Why this answer

Having a pre-negotiated contract reduces the time to engage forensic experts, which is critical during an incident.

2
MCQmedium

A security manager is developing the incident classification scheme for a multinational retailer. The organization must decide how to categorize an incident involving unauthorized access to a database containing 50,000 customer payment card records, where the breach is confirmed but containment has not yet begun. Which factor is MOST important when assigning the incident severity level?

A.The specific malware family or attacker tooling identified during initial triage
B.The number of failed login attempts recorded before the successful breach
C.The potential business impact and regulatory notification obligations arising from the exposed records
D.The elapsed time between the first alert and the analyst's acknowledgment of the ticket
AnswerC

Severity classification must reflect the business impact, including regulatory, financial, and reputational consequences. Exposure of payment card data triggers mandatory notification and potential fines under PCI DSS and privacy regulations. CISM emphasizes that incident prioritization is driven by impact to the organization, not by technical metrics alone, making this the primary factor for assigning severity.

Why this answer

Severity levels exist to drive escalation, resource allocation, and executive notification. The determinant must be the consequence to the business, including legal and regulatory exposure. With confirmed unauthorized access to payment card data, notification obligations and financial impact are concrete and significant.

Technical indicators such as failed logins, malware family, or acknowledgment time inform response but do not define the severity of the incident.

Exam trap

The trap here is assuming that technical indicators like malware type or failed login counts determine severity, when severity must be driven by business and regulatory impact.

3
MCQmedium

During a major cybersecurity incident classified as P1, the incident response team has been activated. The crisis management team (CMT) is also convened. Which of the following is the PRIMARY responsibility of the CMT during this incident?

A.Notifying law enforcement and regulatory bodies immediately.
B.Directly managing the technical containment and eradication of the threat.
C.Making strategic decisions, managing communications, and allocating resources.
D.Performing forensic analysis to identify the root cause of the incident.
AnswerC

Strategic decisions, communications and resource allocation sit with the crisis management team, which handles business-level direction rather than technical containment. This satisfies the stem's P1 constraint: the CMT's mandate is enterprise-wide impact and stakeholder messaging, while the incident response team performs tactical containment and eradication.

Why this answer

The CMT handles strategic decisions, communication, and resource allocation, while the IR team focuses on technical response.

4
MCQeasy

Which type of incident response exercise involves a facilitated discussion of a hypothetical scenario to review plans and procedures?

A.Full-scale exercise
B.Simulation
C.Drill
D.Tabletop exercise
AnswerD

A tabletop exercise gathers stakeholders for a facilitated discussion of a hypothetical scenario, walking through plans and procedures without deploying systems or simulating live traffic. This format directly satisfies the stem's requirement for a discussion-based review, distinguishing it from functional or full-scale exercises that test operational response.

Why this answer

A tabletop exercise is a discussion-based session where participants, guided by a facilitator, walk through a hypothetical incident scenario to evaluate plans, procedures, and decision-making. It does not involve deploying actual resources or simulating live systems; instead, it focuses on reviewing roles, communication, and coordination. This matches the question's description of a facilitated discussion to review plans and procedures.

Other exercise types involve more active or technical execution.

Exam trap

CISM often tests the distinction between discussion-based and operations-based exercises, and candidates may confuse a tabletop exercise with a simulation or drill due to overlapping goals of testing response plans.

How to eliminate wrong answers

Option A is wrong because a full-scale exercise involves actual deployment of resources and personnel in a real-world or simulated operational environment, not just a facilitated discussion. Option B is wrong because a simulation typically uses software or models to replicate system behavior for testing technical responses, which goes beyond a discussion-based review. Option C is wrong because a drill is a coordinated, supervised activity that tests a specific operation or function in a controlled environment, often involving hands-on execution rather than a discussion.

5
MCQeasy

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident, such as ransomware or data breach?

A.Incident response plan
B.Incident response policy
C.Incident response playbook
D.Communication template
AnswerC

A playbook supplies prescriptive, step-by-step procedures for a specific incident type such as ransomware, unlike a policy, which states intent, or a plan, which sets broad structure. It satisfies the need for detailed handling instructions.

Why this answer

Playbooks (or runbooks) provide detailed procedures for specific incident types, while the IR plan is a broader document.

6
MCQhard

During a major incident, the incident response team determines that the attacker used compromised credentials of a privileged administrator. The team wants to prevent the attacker from re-entering while keeping the business running. Which of the following is the MOST appropriate containment action?

A.Enable full packet capture on the network and continue monitoring for attacker activity.
B.Reset the password on the compromised administrator account only and force a change at next logon.
C.Disable the compromised administrator account and rotate all credentials for privileged accounts.
D.Shut down all servers that the administrator account could access until the investigation is complete.
AnswerC

Disabling the compromised account removes the attacker's known access path, and rotating privileged credentials invalidates any other stolen secrets the attacker may hold. This contains the incident without shutting down business operations, which supports the CISM principle of balancing security with business continuity. It also addresses the likelihood that the attacker harvested additional credentials from the compromised administrator's session or memory, closing related entry points.

Why this answer

The most effective containment against credential-based intrusion is to remove the compromised access and invalidate related secrets. Disabling the known compromised administrator account stops the confirmed entry path, while rotating all privileged credentials closes the likely other paths the attacker obtained. This approach contains the threat without unnecessarily halting business operations, which reflects CISM's balance between security response and business continuity.

Blanket shutdowns and passive monitoring fail to remove the adversary's access.

Exam trap

The trap here is treating broad system shutdown as the safest containment, when a proportionate credential-focused action contains the threat with far less business disruption.

7
MCQeasy

An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?

A.The incident response manager
B.The legal counsel
C.The IT director
D.The board of directors or executive management
AnswerD

Board or executive management approval confers enterprise-wide authority and accountability, since only top leadership can mandate compliance across all business units and commit resources. This satisfies the policy's requirement for authority and accountability by placing ownership at the highest governance level.

Why this answer

The IR policy requires senior management approval to demonstrate organizational commitment and allocate necessary resources.

8
MCQeasy

What is the primary purpose of having a pre-established forensic retainer agreement with an external forensics firm?

A.To ensure chain of custody
B.To reduce time to engage during an incident
C.To reduce legal liability
D.To guarantee confidentiality
AnswerB

A pre-established forensic retainer defines scope, rates and contacts in advance, so the firm can be engaged immediately when an incident occurs. This directly satisfies the stem's constraint of reducing engagement delay, avoiding procurement and legal negotiation during the critical containment window when evidence preservation is time-sensitive.

Why this answer

The primary purpose of a pre-established forensic retainer agreement is to reduce the time to engage during an incident. By having a contract already in place, the organization can bypass procurement and legal review delays, enabling the forensics firm to begin work immediately when an incident occurs, which is critical for preserving volatile evidence and minimizing damage.

Exam trap

The trap is that candidates may think the retainer primarily ensures chain of custody or reduces liability, but the CISM exam focuses on the retainer's purpose of enabling rapid engagement during incidents.

How to eliminate wrong answers

Option A is wrong because chain of custody is a procedural and documentation requirement, not a contractual one; a retainer agreement does not directly ensure chain of custody—that is achieved through proper evidence handling and logging. Option C is wrong because while a retainer may include liability clauses, its primary purpose is not to reduce legal liability; liability reduction is a secondary benefit, and the main goal is rapid engagement. Option D is wrong because confidentiality is typically addressed via a separate non-disclosure agreement (NDA) or terms within the retainer, but the retainer's primary purpose is not to guarantee confidentiality—it is to pre-authorize and expedite forensic services.

9
Multi-Selecthard

During a major cybersecurity incident, the crisis management team (CMT) is activated. Which THREE roles are typically part of the CMT? (Select THREE.)

Select 3 answers
A.Chief executive officer (CEO)
B.General counsel (GC)
C.Security analyst
D.Incident response manager
E.Chief financial officer (CFO)
AnswersA, B, E

The CEO sits on the crisis management team to authorise strategic decisions, external communications and resource commitments during a major incident. This satisfies the stem's selection of typical CMT roles, distinguishing executive crisis governance from the tactical incident response team handling containment and recovery.

Why this answer

The Chief Executive Officer (CEO) (A) is a core CMT member because this role owns ultimate business accountability, authorizes major decisions such as taking systems offline or notifying regulators, and communicates with the board and public during a crisis. The General Counsel (GC) (B) belongs on the CMT to assess legal, regulatory, and contractual obligations, including breach-notification laws, litigation risk, and law-enforcement engagement. The Chief Financial Officer (CFO) (E) is included to manage financial impact, authorize emergency spending, handle cyber-insurance claims, and evaluate materiality for financial disclosures.

The Security Analyst (C) is a hands-on technical responder who performs triage, log analysis, and containment tasks rather than strategic crisis-management decisions, so is not typically a CMT member. The Incident Response Manager (D) coordinates the tactical incident-response effort and reports to the CMT, but is not itself a standing CMT role.

Exam trap

The trap here is that candidates confuse the Incident Response Team (IRT) with the Crisis Management Team (CMT), incorrectly selecting operational roles like security analyst or incident response manager instead of the executive leadership roles that constitute the CMT.

10
MCQmedium

An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?

A.Notify law enforcement
B.Increase the ransom payment
C.Escalate to activate the business continuity/disaster recovery plan
D.Engage the forensics firm to preserve evidence
AnswerC

When recovery cannot meet the maximum tolerable downtime, the incident ceases to be a technical problem and becomes a continuity problem. Escalating to activate the business continuity/disaster recovery plan invokes pre-authorised alternate processing arrangements, restoring critical services through failover rather than waiting for server restoration.

Why this answer

When an incident cannot be resolved within MTD, it escalates to business continuity/disaster recovery activation to restore operations.

11
MCQmedium

As part of post-incident activities, an organization schedules a lessons learned meeting. When should this meeting ideally take place?

A.At the next quarterly board meeting
B.Immediately after the incident is detected
C.Only after all legal proceedings are concluded
D.Within 2 weeks of incident resolution
AnswerD

Holding the lessons learned meeting within two weeks of resolution captures details while memories remain fresh and evidence is accessible, yet allows initial recovery to settle. This timing balances accuracy against operational demands, yielding actionable improvements to the incident response programme.

Why this answer

Lessons learned meetings should occur within two weeks of incident resolution while details are fresh, to capture accurate feedback and improve the IR plan.

12
MCQmedium

Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?

A.Pareto analysis
B.SWOT analysis
C.5 Whys
D.Fishbone diagram
AnswerC

5 Whys is an iterative interrogative technique that repeatedly asks 'why' to strip away symptomatic layers and expose the underlying causal factor. Applied after containment, it drills from the immediate ransomware trigger down to the root weakness, satisfying the root cause analysis requirement.

Why this answer

The 5 Whys technique involves repeatedly asking 'why' to drill down from a symptom to its root cause. It was developed by Sakichi Toyoda and is widely used in incident response and quality management. By asking 'why' five times, teams can uncover underlying process failures rather than stopping at superficial causes.

Exam trap

CISM often tests the confusion between root cause analysis tools — candidates may pick Fishbone diagram because it also analyzes causes, but only 5 Whys specifically uses the iterative 'why' questioning.

How to eliminate wrong answers

Option A is wrong because Pareto analysis (80/20 rule) prioritizes issues by frequency or impact, not by drilling down to root cause. Option B is wrong because SWOT analysis assesses strengths, weaknesses, opportunities, and threats, which is a strategic planning tool, not a root cause analysis method. Option D is wrong because a Fishbone diagram (Ishikawa) categorizes potential causes but does not inherently involve the iterative 'why' questioning; it is a visual tool often used in conjunction with 5 Whys.

13
MCQeasy

Which of the following incident categories would typically require the involvement of the crisis management team?

A.A P2 high-severity DDoS attack that has been mitigated within a few hours.
B.A P3 medium-severity insider threat involving unauthorized access to a non-critical system.
C.A P4 low-severity phishing email reported by a user.
D.A P1 critical-severity ransomware attack encrypting critical systems.
AnswerD

A P1 ransomware attack encrypting critical systems threatens business continuity and may involve extortion, regulatory notification and executive decisions beyond IT's authority. This severity and cross-functional impact trigger crisis management team involvement, satisfying the stem's requirement for incidents demanding strategic, organisation-wide response rather than routine technical remediation.

Why this answer

A P1 critical-severity ransomware attack encrypting critical systems requires immediate activation of the crisis management team because it poses an existential threat to business operations, often involving legal, PR, executive, and regulatory stakeholders. The crisis management team handles incidents that exceed the capacity of the incident response team, typically those with high business impact, widespread system compromise, or potential for significant financial/reputational damage.

Exam trap

A common pitfall is to assume that any high-severity technical incident automatically triggers crisis management. However, in the CISM framework, crisis management activation depends on the business impact and the need for executive-level decisions. A quickly mitigated DDoS may be handled by the incident response team alone, whereas a critical ransomware attack affecting core business processes requires crisis management due to the potential for significant financial, legal, and reputational consequences.

How to eliminate wrong answers

Option A is wrong because a P2 high-severity DDoS attack that has been mitigated within a few hours is typically handled by the incident response team using network-layer mitigation techniques (e.g., BGP RTBH, rate-limiting, or scrubbing services) and does not require crisis-level escalation. Option B is wrong because a P3 medium-severity insider threat involving unauthorized access to a non-critical system is a standard incident response task, often investigated by the security operations center (SOC) using log analysis and user behavior analytics (UBA), without needing executive crisis management. Option C is wrong because a P4 low-severity phishing email reported by a user is a routine, low-impact event that is handled through standard security awareness processes and automated email filtering (e.g., SPF, DKIM, DMARC checks), not requiring crisis team involvement.

14
MCQhard

During a major incident, the incident response manager must decide whether to declare a crisis and activate the crisis management team (CMT). Which factor is MOST important in making that decision?

A.The availability of the on-call incident responder during the current shift.
B.Whether the incident was detected by an external party rather than internal monitoring.
C.The potential impact on critical business functions and the need for executive-level coordination.
D.The number of alerts generated by the SIEM in the last hour.
AnswerC

CISM defines crisis declaration around significant business impact and the need for strategic coordination across the organization. When an incident threatens critical business functions, reputation, or regulatory obligations, the CMT should be activated to provide executive direction, prioritize resources, and manage stakeholder communications. This factor directly reflects the purpose of the CMT and is the most reliable basis for the decision.

Why this answer

CISM ties crisis declaration to significant business impact and the need for executive-level coordination. The CMT exists to provide strategic direction, resource prioritization, and stakeholder management during severe incidents. Alert volume, detection source, and shift staffing are operational details that do not by themselves determine whether a crisis should be declared.

Exam trap

The trap here is using technical signals such as alert volume instead of business impact to decide on crisis declaration.

15
MCQeasy

Which role in the incident response team structure is responsible for coordinating all response activities and making decisions about incident severity classification?

A.Incident response manager
B.Communications lead
C.Security analysts
D.Forensic investigators
AnswerA

The incident response manager runs the response end to end, tasking technical teams and assigning severity classifications that trigger escalation and notification thresholds. This satisfies the stem's requirement for the coordinating role, distinguishing it from the executive sponsor's governance remit and the communications lead's messaging duties.

Why this answer

The IR manager leads the team, coordinates activities, and classifies incidents based on severity.

16
MCQhard

A security operations center (SOC) analyst receives an alert about anomalous outbound traffic from a database server to an unfamiliar external IP address. The analyst confirms the traffic is not authorized and suspects data exfiltration. According to CISM incident management principles, which of the following should the analyst do FIRST?

A.Escalate the incident according to the incident response plan and begin documenting actions.
B.Notify law enforcement and the media before performing any internal investigation.
C.Block the external IP address at the firewall to stop the exfiltration immediately.
D.Immediately take the database server offline to prevent further data loss.
AnswerA

Escalating per the incident response plan ensures the right stakeholders are engaged and that actions are coordinated, documented, and authorized. Documentation supports forensic analysis, legal requirements, and post-incident review. This step aligns with CISM principles of following established procedures, maintaining chain of custody, and avoiding unilateral actions that could compromise the investigation or business operations.

Why this answer

The analyst should escalate according to the incident response plan and begin documenting actions. This ensures proper authorization, coordination, and evidence handling before containment or notification. Premature blocking, shutdown, or external notification can tip off attackers, destroy evidence, or create legal and reputational risk.

Following the plan supports a measured, defensible response aligned with CISM incident management principles.

Exam trap

The trap here is assuming the fastest technical action is best, when unauthorized containment or notification can compromise the investigation and business operations.

17
MCQmedium

A security manager is defining the incident classification scheme for a multinational retailer. Executive leadership wants to know which incidents will trigger a formal crisis management team (CMT) activation. Which criterion should PRIMARILY determine whether an incident is classified as a crisis-level event?

A.The incident requires more than one analyst to investigate and remediate within the standard service-level agreement.
B.The incident was detected by the security operations center (SOC) outside of normal business hours.
C.The incident has the potential to cause significant harm to the organization's brand, finances, or regulatory standing.
D.The incident affects a system that is listed in the configuration management database (CMDB) as business-critical.
AnswerC

Crisis classification is driven by potential enterprise-level impact, spanning brand reputation, financial loss, legal or regulatory exposure, and continuity of critical services. When an incident threatens these dimensions beyond the tolerance defined by executive management, the CMT must be activated because response now requires cross-functional executive authority, external communications, and strategic decision-making rather than technical containment alone.

Why this answer

Crisis-level classification hinges on the potential for enterprise-wide harm to reputation, finances, operations, or regulatory compliance. This impact-based threshold ensures the CMT is convened only when executive authority, cross-functional coordination, and external stakeholder management are genuinely required. Detection source, staffing needs, and asset criticality labels are useful inputs but cannot by themselves indicate that an incident has crossed the crisis threshold.

Exam trap

The trap here is assuming that technical severity or asset criticality automatically equals crisis status, when CISM ties crisis classification to realized or potential business impact.

18
MCQmedium

An organization's incident response team has contained a data breach. Legal counsel has advised that litigation is likely. Which of the following actions should the team take to preserve evidence?

A.Issue a legal hold and create forensic images of affected systems
B.Immediately wipe affected systems to prevent further data loss
C.Notify the affected individuals as required by law
D.Delete all logs to avoid exposing sensitive information
AnswerA

A legal hold suspends routine deletion and triggers preservation obligations, while forensic imaging captures a bit-for-bit copy without altering the original media. Together they satisfy the litigation constraint by keeping evidence admissible and unmodified, which mere containment or continued live analysis would jeopardise.

Why this answer

When litigation is anticipated, a legal hold must be issued to prevent destruction of relevant evidence, and forensic copies should be made before remediation.

19
MCQhard

An incident response team is handling a supply chain compromise that has affected a critical business process. The estimated recovery time exceeds the maximum tolerable downtime (MTD). What should the incident manager do NEXT?

A.Notify affected customers of the expected delay
B.Continue containment efforts and hope for a faster recovery
C.Escalate to the BC/DR team and the authority who can declare a disaster
D.Shut down the affected system to prevent further impact
AnswerC

When recovery exceeds the maximum tolerable downtime, the incident manager must escalate to the BC/DR team and the authority empowered to declare a disaster, since only that authority can activate continuity arrangements and commit resources beyond the IR team's remit. Continuing technical recovery alone would breach the MTD.

Why this answer

When MTD is exceeded, the incident escalates to business continuity/disaster recovery activation. The BC/DR decision authority should be notified to declare a disaster and activate recovery plans.

20
MCQeasy

A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?

A.Shut down the workstation to stop the malware.
B.Notify the CEO and board of directors about the incident.
C.Run a full antivirus scan on the workstation.
D.Isolate the workstation from the network to prevent further communication.
AnswerD

Isolating the workstation is the immediate containment step that stops the malware from communicating with the command-and-control server and prevents potential lateral movement or data exfiltration. This aligns with the containment phase of incident response. Once isolated, the team can conduct a thorough investigation and remediation without the risk of the attacker continuing to operate.

Why this answer

When a true positive is confirmed, the immediate priority is containment to stop the threat from spreading or causing further harm. Isolating the workstation cuts off command-and-control communication while preserving the system for investigation. This follows the standard incident response sequence of identification, containment, eradication, and recovery, and supports both security and forensic objectives.

Exam trap

The trap here is choosing to shut down or scan the workstation first, which can either destroy evidence or leave the attacker connected, instead of isolating it to contain the threat.

21
MCQmedium

A financial services firm has activated its crisis management team (CMT) for a significant data breach. The CISO, who is a member of the CMT, is asked to present the technical details of the incident. However, the CMT's primary focus should be on which of the following?

A.Making strategic decisions regarding business continuity and stakeholder communication.
B.Coordinating the technical recovery of affected systems.
C.Conducting a forensic analysis to determine the root cause.
D.Directly managing the incident response team's daily activities.
AnswerA

The CMT is responsible for strategic decision-making during a crisis, including ensuring business continuity, managing communications with stakeholders, and aligning incident response with organizational objectives. Technical details are important but are inputs to these decisions. The CMT focuses on the big picture, such as whether to shut down systems, how to inform customers, and how to maintain trust.

Why this answer

The CMT's primary role during a major incident is to make strategic decisions that affect the entire organization, such as business continuity, resource allocation, and stakeholder communication. While technical input is valuable, the CMT must focus on the broader impact and ensure that the response aligns with business objectives. This separation of strategic and tactical responsibilities is a key CISM principle.

Exam trap

The trap here is assuming the CMT is involved in technical recovery or forensic analysis, when its focus is strategic business decisions.

22
Multi-Selectmedium

Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Select TWO.)

Select 2 answers
A.An insurance claim form for cyber incidents
B.A signed retainer agreement with a forensics firm
C.A list of affected customers from the most recent data breach
D.A root cause analysis report from a previous incident
E.An incident response team with assigned roles and responsibilities
AnswersB, E

A pre-negotiated retainer with a forensics firm guarantees specialist capacity and defined rates are available immediately, avoiding procurement delays during containment. This satisfies the stem's requirement that the component be established before an incident occurs, since forensic demand spikes and vendors cannot be onboarded mid-crisis.

Why this answer

Option B is correct because a signed retainer agreement with a forensics firm is a pre-established arrangement that guarantees rapid access to specialized digital forensics and incident handling expertise when an incident occurs, avoiding delays from procurement or negotiation during a crisis. Option E is correct because an incident response team with clearly assigned roles and responsibilities is a foundational element of any incident response programme, ensuring that containment, eradication, recovery, and communication tasks are executed by accountable personnel per the incident response plan. The remaining options are not essential pre-incident components: A (an insurance claim form) is used after an incident to seek reimbursement, C (a list of affected customers) is an output of breach investigation and notification rather than a preparatory component, and D (a root cause analysis report from a previous incident) is a post-incident artifact that may inform lessons learned but is not required to establish the programme.

23
MCQmedium

A security analyst detects a series of failed login attempts followed by a successful login from an unusual geographic location. The account is a standard user account. Which incident category best describes this scenario?

A.Data breach
B.Supply chain attack
C.Insider threat
D.Account compromise
AnswerD

Failed logins followed by a successful login from an unusual location indicate credentials were obtained and used by an unauthorised party, which is account compromise. Brute force alone would show only failures; this pattern confirms access succeeded.

Why this answer

The scenario describes an account compromise where credentials are likely stolen and used to gain unauthorized access.

24
Multi-Selectmedium

Which THREE of the following should be included in an incident communication template?

Select 3 answers
A.Affected systems or data
B.Description of the incident
C.Actions to be taken by recipients
D.Technical indicators of compromise (IoCs)
E.Attribution of the attacker
AnswersA, B, C

Naming affected systems or data tells recipients the incident's scope, so they can judge exposure and prioritise their own checks. This satisfies the template's need to convey impact precisely, rather than leaving recipients guessing which assets are involved.

Why this answer

Option A (Affected systems or data) is correct because an incident communication template must clearly identify the scope of impact—which systems, services, or data sets are involved—so recipients understand what is at risk and can prioritize their response. Option B (Description of the incident) is correct because the template needs a concise, accurate summary of what happened (e.g., type of incident, time of detection, current status) to give recipients the context required to act appropriately. Option C (Actions to be taken by recipients) is correct because the primary purpose of incident communications is to direct the audience—users, IT staff, or stakeholders—on specific steps such as disconnecting from the network, resetting passwords, or awaiting further instructions.

Option D (Technical indicators of compromise) is not included because IoCs such as IP addresses, hashes, and domain names belong in threat intelligence or technical investigation reports, not in a general communication template intended for broad audiences. Option E (Attribution of the attacker) is not included because attribution is typically uncertain, sensitive, and often irrelevant to the immediate protective actions recipients must take, making it inappropriate for a standard incident communication template.

Exam trap

CISM often tests the confusion between technical incident artifacts (IoCs, attribution) and stakeholder communication content — candidates who include IoCs or attribution in a general template miss that communication templates are audience-scoped and should avoid unverified or overly technical details.

25
MCQmedium

Which of the following is a key objective of sharing threat intelligence, such as indicators of compromise (IoCs), with an Information Sharing and Analysis Center (ISAC)?

A.To document the incident for insurance claims
B.To market the organization's security capabilities
C.To receive timely threat information and contribute to community defense
D.To fulfill regulatory requirements for public disclosure
AnswerC

ISAC membership is bidirectional: members submit IoCs and receive aggregated, sector-specific threat intelligence and early warnings. This reciprocal exchange satisfies the objective of gaining timely threat information while strengthening collective defence, which unilateral internal monitoring cannot deliver.

Why this answer

The primary objective of sharing IoCs with an ISAC is bidirectional: the organization receives timely, sector-specific threat intelligence from peers and contributes its own observations to strengthen collective defense. ISACs are sector-based (e.g., FS-ISAC for financial services, H-ISAC for healthcare) and enable early warning of emerging threats. This mutual benefit is the core purpose of threat intelligence sharing.

Exam trap

CISM often tests the confusion between compliance-driven disclosure (regulatory reporting) and voluntary, mutual-benefit threat intelligence sharing — candidates may pick the regulatory option because it sounds authoritative.

How to eliminate wrong answers

Option A is wrong because documenting incidents for insurance claims is an internal risk-management activity, not the purpose of ISAC participation. Option B is wrong because marketing security capabilities is not a security objective and is contrary to the trust-based, often anonymized nature of ISAC sharing. Option D is wrong because while some regulations encourage or require threat sharing, the primary objective of ISAC participation is operational threat intelligence and community defense, not regulatory checkbox compliance.

26
Multi-Selectmedium

An organization is developing its incident response plan and wants to ensure that it has the necessary authority and communication channels in place before an incident occurs. Which TWO of the following should be established to enable effective incident response? (Choose two.)

Select 2 answers
A.A list of all employees' personal social media accounts for monitoring.
B.A policy requiring all incidents to be resolved within one hour of detection.
C.A backup of all incident response team members' personal devices.
D.A predefined incident response team with clearly defined roles and responsibilities.
E.A communication plan that includes internal and external stakeholders, with predefined templates and contact information.
AnswersD, E

A predefined team with clear roles ensures that during an incident, personnel know exactly what to do, who to report to, and what decisions they are authorized to make. This reduces confusion and delays. CISM emphasizes that incident response planning must include an organizational structure with defined responsibilities, escalation paths, and decision-making authority to enable a coordinated and timely response.

Why this answer

Effective incident response requires a predefined team with clear roles and a robust communication plan. These elements ensure that during an incident, responsibilities are understood and information flows to the right stakeholders in a timely manner. Together, they provide the authority and coordination needed to execute the response plan, aligning with CISM's emphasis on preparation and governance.

Exam trap

The trap here is selecting options that sound like security measures but are unrelated to incident response planning, such as monitoring personal social media or setting arbitrary resolution deadlines.

27
MCQhard

During a data breach investigation, the legal counsel advises the incident response team to ensure that communications with external forensic experts are protected by attorney-client privilege. Which action best preserves this privilege?

A.Using a pre-existing retainer agreement without legal involvement
B.Having the forensic firm report directly to the CISO
C.Having the forensic firm sign a non-disclosure agreement
D.Engaging the forensic firm through legal counsel and ensuring that their work is done at the direction of legal
AnswerD

Routing the forensic engagement through legal counsel, with the firm working at counsel's direction, brings the work product within attorney-client privilege and the work-product doctrine. This satisfies the stem's constraint that external expert communications remain legally protected during breach investigation.

Why this answer

Attorney-client privilege is preserved when the forensic firm is engaged by and works at the direction of legal counsel, so their communications and work product fall under the privilege umbrella. This structure ensures the forensic investigation is treated as legal work rather than ordinary business consulting. NDAs and reporting lines do not create privilege.

Exam trap

CISM often tests the misconception that an NDA or a retainer alone preserves privilege; the trap is failing to recognize that privilege requires the forensic firm to be engaged through and directed by legal counsel.

How to eliminate wrong answers

Option A is wrong because a pre-existing retainer without legal involvement does not establish the attorney-client relationship or legal direction needed for privilege to attach to the forensic work. Option B is wrong because having the forensic firm report directly to the CISO places the work in the business/IT chain, which can waive or prevent privilege from applying. Option C is wrong because an NDA protects confidentiality contractually but does not create attorney-client privilege; privilege requires legal engagement and direction.

28
MCQmedium

Which post-incident activity involves identifying the technical cause, the process failure that allowed it, and the management/governance failure that permitted the process failure?

A.Lessons learned meeting
B.Incident closure report
C.Root cause analysis (RCA)
D.Threat intelligence sharing
AnswerC

RCA uniquely spans all three layers named in the stem: technical cause, the process failure enabling it, and the governance failure permitting that process weakness. Other post-incident activities, such as lessons learned meetings or metric reporting, address only one layer.

Why this answer

Root cause analysis (RCA) digs into multiple layers to find underlying issues, often using techniques like 5 Whys or fishbone diagrams.

29
MCQeasy

What is the PRIMARY reason for having an incident response team roster and contact list readily available?

A.To satisfy regulatory compliance requirements.
B.To ensure all team members have the necessary training.
C.To provide a list for auditors to review.
D.To enable quick activation of the incident response team.
AnswerD

A current roster with verified contact details removes the delay of identifying and locating team members during an incident. That directly enables rapid activation, ensuring the right responders engage immediately rather than losing critical containment time.

Why this answer

Rapid activation of the IR team depends on knowing who to contact and their backup.

30
MCQhard

During a major incident, the incident response team determines that a compromised server must be rebuilt immediately to restore a critical service. A forensic analyst objects, noting that the server contains evidence relevant to a pending regulatory investigation. How should the incident manager resolve this conflict?

A.Proceed with the rebuild because restoring the critical service takes priority over any investigative activity.
B.Rebuild the server and rely on the SIEM logs to reconstruct the evidence needed for the investigation.
C.Delay the rebuild until the regulatory investigation concludes so that the server remains untouched.
D.Capture a forensic image of the server's storage and volatile memory before rebuilding, then document the evidence handling.
AnswerD

Preserving a forensic image of both persistent storage and volatile memory satisfies the investigator's need for evidence while allowing the rebuild to proceed. This approach respects the pending regulatory investigation and maintains chain of custody, which is essential if the evidence is later challenged. CISM supports continuity of operations balanced with legal preservation, making this the appropriate resolution of the conflict.

Why this answer

When operational recovery and evidence preservation collide, the incident manager should pursue both by imaging the system before it is rebuilt. A forensic image of storage and memory preserves the artifacts regulators and investigators require while allowing the critical service to be restored. This balanced action aligns with CISM guidance to integrate incident response with legal and regulatory obligations rather than sacrificing one for the other.

Exam trap

The trap here is treating recovery and evidence preservation as mutually exclusive, when capturing a forensic image allows both objectives to be met.

31
Multi-Selectmedium

Which TWO of the following are typical notification deadlines for regulatory reporting of a data breach? (Select two.)

Select 2 answers
A.4 business days (SEC proposed)
B.30 days
C.72 hours (GDPR)
D.7 days
E.24 hours
AnswersA, C

The SEC's proposed rule requires registrants to report material cybersecurity incidents on Form 8-K within four business days of determining materiality, satisfying the stem's regulatory notification deadline. This fixed, short window reflects the US securities regime's emphasis on prompt investor disclosure, distinct from GDPR's 72-hour supervisory authority timescale.

Why this answer

Option A (4 business days, SEC proposed) is correct because the U.S. Securities and Exchange Commission's proposed rules for public companies would require disclosure of material cybersecurity incidents on Form 8-K within four business days of determining that the incident is material. Option C (72 hours, GDPR) is correct because Article 33 of the EU General Data Protection Regulation requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it.

The remaining options do not match these regulatory frameworks: 30 days (B) is not the standard GDPR or SEC notification deadline, 7 days (D) is not specified by either regime, and 24 hours (E) is a shorter window than either the SEC's four-business-day or GDPR's 72-hour requirement.

32
MCQmedium

Which of the following is the PRIMARY role of the executive sponsor in the incident response team structure?

A.To handle all media inquiries and public relations.
B.To serve as legal counsel and ensure compliance.
C.To provide strategic direction, resources, and decision-making authority.
D.To manage the technical investigation and forensic analysis.
AnswerC

The executive sponsor supplies strategic direction, budget and decision-making authority, satisfying the stem's requirement for executive-level governance during incidents. This role resolves escalated business-impact decisions and authorises resource commitments that operational responders cannot make, distinguishing it from tactical containment or forensic investigation duties.

Why this answer

The executive sponsor provides authority, resources, and strategic direction, and ensures the IR team has the support needed to respond effectively.

33
MCQmedium

An organization's security operations center (SOC) confirms that a production database server is actively exfiltrating customer records to an external IP address. The SOC manager must decide whether to immediately isolate the server from the network. Which factor should PRIMARILY guide this decision?

A.The number of failed login attempts recorded on the database server in the preceding 24 hours.
B.Whether the database server is covered by the organization's cyber insurance policy.
C.Whether the external IP address has been previously reported to a threat intelligence sharing platform.
D.The potential business impact of taking the server offline versus the value of preserving evidence of the exfiltration channel.
AnswerD

Isolation decisions during an active exfiltration hinge on balancing containment against operational and evidentiary consequences. Cutting the network link stops data loss but may destroy volatile evidence such as live network connections and in-memory artifacts, and can disrupt critical business services. CISM emphasizes that containment strategy must weigh business impact, legal obligations, and evidence preservation before acting, making this the primary guiding factor.

Why this answer

Containment during active exfiltration requires balancing the harm of continued data loss against the harm of disrupting production services and destroying volatile evidence. CISM frames incident response decisions around business impact and evidence integrity, so the decision to isolate must be grounded in that trade-off rather than in threat intelligence reputation, authentication telemetry, or insurance considerations.

Exam trap

The trap here is assuming that any confirmed exfiltration automatically mandates immediate isolation, ignoring that containment choices must be weighed against business impact and evidence preservation.

34
MCQhard

An organization has just experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

A.48 hours
B.7 days
C.24 hours
D.72 hours
AnswerD

GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk. This fixed deadline satisfies the stem's maximum timeframe constraint for EU resident data.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of the breach.

35
MCQmedium

A security manager is drafting the escalation criteria for the incident response plan. The organisation wants to ensure that incidents are escalated to the crisis management team (CMT) appropriately. Which of the following is the BEST basis for defining when an incident should be escalated to the CMT?

A.The incident has the potential to cause significant business, financial, legal, or reputational impact.
B.The incident was reported by an external party such as a customer or partner.
C.The incident involves more than one server or endpoint in the environment.
D.The incident was detected outside normal business hours or on a weekend.
AnswerA

The CMT exists to manage enterprise-level consequences, so escalation criteria should be tied to potential business impact rather than technical characteristics. Significant financial, legal, regulatory, or reputational exposure requires executive coordination across functions. CISM defines crisis management as the discipline of managing the wider business effects of an incident. Using impact thresholds ensures the right incidents reach the CMT without flooding it with routine technical events.

Why this answer

Escalation to the crisis management team should be driven by the potential business consequences of an incident. Criteria based on financial, legal, regulatory, or reputational impact ensure that enterprise-level events receive executive coordination while routine technical incidents remain with the incident response team. Detection timing, system count, and reporting source are technical or circumstantial factors that do not reliably indicate crisis-level impact and can cause inappropriate escalation decisions.

Exam trap

The trap here is selecting a technical or circumstantial trigger such as number of systems or time of detection, instead of the business impact that defines a crisis.

36
MCQeasy

Which incident severity level requires executive notification and 24/7 response, and has major business impact?

A.P3 - Medium
B.P1 - Critical
C.P2 - High
D.P4 - Low
AnswerB

P1 – Critical incidents demand immediate 24/7 response and executive notification because they cause major business impact, such as widespread service outage or data breach. This severity tier exists precisely to trigger escalation to leadership, satisfying the stem's requirement for executive involvement alongside continuous remediation until service restoration.

Why this answer

P1 (Critical) incidents have major business impact, require executive notification, and demand a 24/7 response effort.

37
MCQeasy

A security analyst receives an alert from the SIEM indicating that a user account has been added to the domain administrators group outside of the change management window. The analyst confirms the change was not authorized. According to CISM incident management principles, what should the analyst do FIRST?

A.Document the alert in the ticketing system and continue monitoring for additional related events before escalating.
B.Remove the account from the domain administrators group to immediately reverse the unauthorized change.
C.Escalate the alert to the incident response team according to the documented incident classification and escalation procedures.
D.Contact the user whose account was added to the domain administrators group to ask if they made the change.
AnswerC

Unauthorized privileged account creation is a potential security incident that must be escalated promptly through the established incident response process. The analyst's first duty is to recognize and report, not to remediate independently. Following the documented classification and escalation path ensures the right resources are engaged and that the incident is tracked, prioritized, and handled consistently. This preserves the integrity of the response process and aligns with CISM's emphasis on defined roles and procedures.

Why this answer

The analyst should escalate the unauthorized privileged account change through the documented incident classification and escalation procedures. This ensures the incident receives appropriate resources and is handled consistently, while preserving evidence and avoiding premature or unilateral actions. Reversing the change, contacting the user, or simply monitoring can compromise the investigation or allow the attacker to expand access.

Exam trap

The trap here is believing that a monitoring analyst should immediately fix or investigate the issue personally, rather than escalate it through the incident response process.

38
MCQmedium

A security manager learns that a production database containing customer records was copied to an unauthorized external drive by a contractor. The incident response team has contained the contractor's access. According to CISM best practices, which action should the security manager take NEXT?

A.Terminate the contractor's employment contract and demand return of the external drive.
B.Notify the legal department and initiate the evidence preservation and chain-of-custody process.
C.Send a company-wide email informing all employees about the contractor's misconduct.
D.Immediately delete the contractor's user account and all associated files to prevent further data loss.
AnswerB

Because the contractor's actions may constitute a criminal offense or trigger regulatory notification duties, the security manager must involve legal counsel immediately and ensure forensic evidence is preserved with documented chain of custody. This protects the organization's ability to pursue legal action, support law enforcement, and meet breach notification obligations. Preserving evidence before any further system changes prevents spoliation and keeps the investigation defensible.

Why this answer

When an incident may involve criminal conduct or regulatory breach notification, the security manager's immediate priority is to engage legal counsel and preserve evidence. This ensures the organization can support law enforcement, defend against liability, and meet notification requirements. Containment has already occurred, so the next step is protecting the integrity of the investigation rather than taking destructive or premature personnel actions.

Exam trap

The trap here is assuming that containment means the incident is over and that administrative actions like termination or account deletion can proceed without first preserving evidence and consulting legal counsel.

39
MCQmedium

Which of the following incident types is MOST likely to require activation of the crisis management team (CMT) due to potential regulatory and reputational impact?

A.A P1 data breach involving customer personally identifiable information (PII).
B.A P2 denial-of-service attack that is quickly mitigated.
C.A P4 phishing email reported by a user.
D.A P3 insider threat involving an employee accessing unauthorized files.
AnswerA

A P1 breach of customer PII triggers notification duties under GDPR and similar regimes, plus severe reputational fallout. That combination of regulatory exposure and public trust damage exceeds routine IR handling, so the crisis management team must be activated to coordinate legal, communications and executive response.

Why this answer

A P1 data breach involving customer PII triggers mandatory breach notification laws (e.g., GDPR Article 33, HIPAA Breach Notification Rule) and often requires immediate CMT activation to manage regulatory filings, legal liability, and public relations. The CMT is designed for high-severity incidents with significant business, legal, or reputational consequences, which a P1 breach directly entails.

Exam trap

The trap here is that candidates may confuse technical severity (e.g., a DDoS causing downtime) with business/regulatory impact, failing to recognize that only incidents with legal or reputational fallout (like a PII breach) necessitate CMT activation, not merely high technical severity.

How to eliminate wrong answers

Option B is wrong because a P2 denial-of-service attack that is quickly mitigated typically does not involve data loss or regulatory notification requirements, so it would be handled by the technical incident response team without CMT escalation. Option C is wrong because a P4 phishing email reported by a user is a low-severity, routine event that is usually handled via standard security awareness processes and does not warrant CMT involvement. Option D is wrong because a P3 insider threat involving unauthorized file access, while serious, is typically contained and investigated by the incident response team and HR, and only escalates to the CMT if it leads to a confirmed data breach or regulatory exposure.

40
MCQeasy

Which of the following is the primary reason for conducting a lessons learned meeting after an incident?

A.To document the incident for insurance
B.To update the IR plan and playbooks
C.To satisfy regulatory requirements
D.To assign blame
AnswerB

Capturing what worked and failed during response feeds directly into revising the IR plan and playbooks, satisfying the stem's demand for the primary reason. This closes the improvement loop, embedding corrective actions into future response procedures rather than merely documenting the incident for compliance or post-mortem reporting purposes.

Why this answer

The lessons learned meeting aims to identify improvements to the incident response process.

41
MCQeasy

Which of the following is the PRIMARY reason for including communication templates in the incident response plan?

A.To reduce the workload on the communications lead.
B.To comply with regulatory requirements for breach notification.
C.To ensure consistent and timely messaging to stakeholders.
D.To avoid legal liability by using approved language.
AnswerC

Pre-approved templates remove drafting delays and standardise wording, so stakeholders receive accurate, timely notifications during high-pressure incidents. This directly satisfies the stem's primary-reason constraint: communication speed and consistency, rather than investigation, containment or forensic accuracy, which other options address.

Why this answer

Communication templates ensure that notifications are consistent, accurate, and timely during the stress of an incident, reducing the risk of errors or omissions.

42
MCQhard

During a major incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the communications lead on the CMT?

A.Coordinating all external and internal communications
B.Authorizing financial expenditures for incident response
C.Directing technical containment efforts
D.Preserving digital evidence for litigation
AnswerA

The communications lead owns the single authoritative voice during a major incident, coordinating internal staff messaging and external stakeholder, media, and regulator communications. This prevents conflicting statements and satisfies the stem's requirement for unified crisis messaging under CMT direction.

Why this answer

The communications lead on a Crisis Management Team (CMT) is specifically designated to own the communications function during an incident — both internal (employees, executives, board) and external (customers, media, regulators, law enforcement). This role ensures a single, consistent, approved message is delivered to all stakeholders, preventing conflicting or premature disclosures that could escalate reputational and legal exposure.

Exam trap

CISM often tests role clarity within the CMT — candidates confuse the communications lead's coordination duty with the technical, financial, or legal responsibilities owned by other CMT members.

How to eliminate wrong answers

Option B is wrong because financial authorization is the responsibility of the CFO, finance lead, or incident sponsor — not the communications lead, who typically has no budget authority. Option C is wrong because directing technical containment is the role of the technical/IT lead or incident response manager, not communications. Option D is wrong because evidence preservation is the responsibility of the forensics/legal team (often coordinated with counsel to maintain chain of custody), not the communications function.

43
MCQmedium

An organization's incident response plan requires that evidence be preserved for potential litigation. Which of the following actions is MOST critical to ensure the admissibility of digital evidence?

A.Storing evidence in a secure, access-controlled location.
B.Creating forensic images of all affected systems before remediation.
C.Encrypting all evidence files to prevent unauthorized access.
D.Documenting the chain of custody for all evidence collected.
AnswerD

Documenting the chain of custody provides an unbroken, auditable record of who handled each artefact, when, and for what purpose. This directly satisfies the litigation constraint in the stem, since courts require proof that evidence remained unaltered from seizure to presentation; gaps or undocumented transfers render it inadmissible regardless of technical accuracy.

Why this answer

Admissibility of digital evidence in court hinges on demonstrating that the evidence has not been tampered with from the moment of collection to presentation. The chain of custody is the legally mandated documentation that tracks every person who handled the evidence, the time and date of each transfer, and the purpose of each action. Without a complete and verifiable chain of custody, the opposing counsel can successfully argue that the evidence may have been altered, making it inadmissible regardless of how securely it was stored or imaged.

Exam trap

The trap here is that candidates confuse operational best practices (like creating forensic images or securing evidence) with the legal requirement for admissibility, which is fundamentally about proving an unbroken chain of custody through meticulous documentation.

How to eliminate wrong answers

Option A is wrong because storing evidence in a secure, access-controlled location protects its integrity but does not create the legal record required to prove that integrity in court; a secure location alone cannot rebut allegations of tampering without documented custody transfers. Option B is wrong because creating forensic images before remediation is a best practice for preserving evidence, but the images themselves are useless for litigation if the chain of custody is not documented; the image must be accompanied by a hash (e.g., SHA-256) and a custody log to be admissible. Option C is wrong because encrypting evidence files prevents unauthorized access but introduces a separate admissibility hurdle: if the encryption key is lost or the decryption process cannot be verified, the evidence may be deemed inaccessible or its integrity questioned; encryption does not replace the need for a documented chain of custody.

44
MCQeasy

Which incident severity level is characterized by major business impact, requires executive notification, and demands 24/7 response?

A.P3 — Medium
B.P2 — High
C.P4 — Low
D.P1 — Critical
AnswerD

P1 critical is defined by major business impact, executive notification and continuous 24/7 response. The stem's three constraints — severe impact, executive escalation and round-the-clock engagement — map precisely onto this highest severity tier, distinguishing it from P2's business-hours handling.

Why this answer

P1 (critical) incidents have the highest severity and require immediate, around-the-clock response.

45
MCQmedium

After a P2 (high) incident is resolved, the incident response team conducts a lessons learned meeting. Which timeframe is most appropriate for holding this meeting?

A.Immediately after containment
B.Only after the root cause analysis is completed
C.Within 2 weeks of incident resolution
D.Within 30 days of incident resolution
AnswerC

Holding the review within two weeks balances memory retention against operational recovery, satisfying the stem's post-resolution timing constraint. Participants still recall technical details and decisions while the incident remains relevant, yet have had sufficient time to decompress. This window also allows evidence gathering and timeline reconstruction before details fade or staff rotate.

Why this answer

Holding the lessons learned meeting within about two weeks of resolution balances memory freshness with enough time to gather facts and complete preliminary analysis. It is soon enough that details are still accurate but late enough that the team is no longer in firefighting mode. This aligns with common IR frameworks like NIST SP 800-61.

Exam trap

CISM often tests the tension between 'as soon as possible' and 'after enough analysis' — the correct answer is a middle-ground timeframe, not the extreme.

How to eliminate wrong answers

Option A is wrong because immediately after containment the team is still stabilizing the environment and lacks the full picture needed for meaningful lessons. Option B is wrong because waiting for a complete root cause analysis can take weeks or months, causing memory decay and delaying improvements. Option D is wrong because 30 days is too long — details fade, personnel move on, and corrective actions lose urgency.

46
MCQhard

During a major incident, the incident response manager is coordinating containment while the crisis management team (CMT) handles business continuity decisions. A responder proposes immediately wiping and rebuilding an affected server to restore service quickly, but the server contains evidence relevant to a potential legal action. Which of the following is the MOST appropriate action for the incident response manager to take?

A.Delegate the decision entirely to the forensic investigator and proceed based on their technical recommendation alone.
B.Consult legal counsel to determine preservation obligations, then choose a containment or recovery approach that preserves evidence while restoring service.
C.Refuse to restore service until the forensic investigation is fully complete, regardless of business impact.
D.Authorize the rebuild immediately because restoring service takes precedence over evidence preservation in all incidents.
AnswerB

Legal counsel determines whether a litigation hold or preservation duty applies, and the response must respect that obligation. The manager can often restore service using alternate infrastructure, network isolation, or forensic imaging before rebuild, satisfying both operational and legal needs. Consulting counsel first ensures the chosen containment method does not inadvertently destroy evidence and keeps the response defensible.

Why this answer

When legal action is anticipated, evidence preservation becomes a formal obligation that must be balanced against service restoration. The incident response manager should engage legal counsel to confirm preservation requirements, then select a containment or recovery method that keeps evidence intact, such as imaging the server or rebuilding on alternate infrastructure. This coordinated approach protects both operational continuity and the organization's legal position, avoiding the extremes of reckless destruction or unnecessary service outage.

Exam trap

The trap here is treating service restoration and evidence preservation as mutually exclusive, when in practice legal guidance plus forensic imaging or alternate infrastructure can satisfy both obligations.

47
Multi-Selecthard

Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)

Select 3 answers
A.Updating incident response plans and playbooks based on lessons learned
B.Activating the disaster recovery site
C.Conducting root cause analysis using techniques like 5 Whys
D.Sharing indicators of compromise with relevant ISACs
E.Implementing immediate containment measures
AnswersA, C, D

Feeding lessons learned back into plans and playbooks closes the improvement loop, ensuring the next incident is handled better. This directly satisfies the post-incident phase's objective of institutionalising corrective actions rather than merely restoring service.

Why this answer

Option A is correct because the post-incident phase includes reviewing what happened and feeding lessons learned back into the incident response plan and playbooks so future responses improve. Option C is correct because root cause analysis, often using techniques such as 5 Whys or fishbone diagrams, is a core post-incident activity that identifies the underlying cause rather than just the symptom. Option D is correct because sharing indicators of compromise with relevant Information Sharing and Analysis Centers (ISACs) is a post-incident coordination activity that helps the broader community detect and defend against the same threat.

Option B is not correct because activating the disaster recovery site is a response or recovery action, not a post-incident review activity. Option E is not correct because implementing immediate containment measures occurs during the containment phase of incident response, before the post-incident phase begins.

48
MCQmedium

After a data breach incident, the incident response team must preserve evidence for potential litigation. Which of the following actions should be taken FIRST?

A.Update the IR plan
B.Begin remediation
C.Notify law enforcement
D.Issue a legal hold
AnswerD

A legal hold must be issued first because it immediately suspends routine deletion and alteration of potentially relevant data, preserving evidence and avoiding spoliation sanctions. Subsequent forensic imaging and collection then proceed under that hold's protection.

Why this answer

Issuing a legal hold is the first action because it triggers the duty to preserve evidence and suspends normal data retention or deletion policies, ensuring that logs, disk images, and other artifacts are not destroyed. Under FRCP and similar rules, once litigation is reasonably anticipated, spoliation of evidence can lead to sanctions, so the legal hold must precede any remediation or notification. This step also formally directs custodians and IT staff to retain relevant records, creating a defensible chain of custody.

Exam trap

CISM often tests the misconception that notifying law enforcement or starting remediation is the immediate priority, but the first action in any potential litigation scenario is always to preserve evidence via a legal hold.

How to eliminate wrong answers

Option A is wrong because updating the IR plan is a post-incident improvement activity that does not preserve evidence and can wait until after the legal hold is in place. Option B is wrong because beginning remediation can alter or destroy volatile evidence (e.g., rebooting systems, deleting malware), directly conflicting with the duty to preserve. Option C is wrong because notifying law enforcement, while potentially required, does not itself impose a preservation obligation and may even be premature before internal legal hold procedures are activated.

49
MCQeasy

Which of the following is the PRIMARY purpose of having a pre-established contract with a digital forensics firm before an incident occurs?

A.To ensure attorney-client privilege is automatically applied
B.To ensure the firm is available 24/7
C.To guarantee a discounted rate
D.To reduce the time required to engage the firm during an incident
AnswerD

A retainer establishes pre-negotiated rates, scopes and call-out procedures, so the firm can be mobilised immediately rather than negotiating terms mid-incident. That directly satisfies the stem's constraint of reducing engagement time when every hour of dwell time increases damage.

Why this answer

The primary purpose of a pre-established contract with a digital forensics firm is to eliminate procurement delays during an incident. When an incident occurs, time is critical; having a signed contract in place allows the firm to be engaged immediately without waiting for legal or administrative approvals, which directly supports the incident response goal of minimizing damage and preserving evidence.

Exam trap

The trap here is that candidates confuse a secondary benefit (like cost savings or availability) with the primary operational goal of reducing engagement time, which is the core driver in incident management scenarios.

How to eliminate wrong answers

Option A is wrong because attorney-client privilege is not automatically applied by a contract; it requires specific legal agreements and actions (e.g., engaging counsel to direct the work under privilege rules), and a pre-established contract alone does not guarantee this protection. Option B is wrong while availability is a benefit, it is not the primary purpose; 24/7 availability can be arranged without a pre-established contract, and the core issue is reducing engagement time, not just availability. Option C is wrong because discounted rates are a secondary commercial benefit, not the primary purpose; the main driver is operational efficiency during an incident, not cost savings.

50
MCQhard

A security operations center (SOC) analyst receives an alert about a possible data exfiltration from a database server. The analyst must determine the incident severity to initiate the appropriate response. Which of the following factors is MOST important in determining the severity level?

A.The volume of data potentially exfiltrated.
B.The source IP address of the exfiltration attempt.
C.The potential impact on business operations and regulatory compliance.
D.The method used to detect the exfiltration (e.g., SIEM alert vs. user report).
AnswerC

This is correct because severity should be based on the potential impact to the business, including financial, operational, legal, and reputational consequences. CISM emphasizes that incident severity must reflect business impact. The volume, source, and detection method are secondary to the actual or potential harm to the organization.

Why this answer

Incident severity should be determined by the potential impact on business operations, regulatory compliance, and reputation. CISM stresses that severity classification drives the response level and resource allocation. While data volume, source IP, and detection method are relevant details, they do not define severity.

The most important factor is the business impact, as it determines the urgency and scale of the response.

Exam trap

The trap here is equating the volume of data with severity, overlooking that a small breach of highly sensitive data can be far more severe than a large breach of non-sensitive data.

51
MCQhard

During a live intrusion, the incident response lead must decide how the team will communicate. The attackers are believed to be monitoring the corporate email and collaboration platform. Which of the following is the MOST appropriate action to maintain confidentiality of incident communications?

A.Continue using the existing collaboration platform but add a second factor to all responder accounts.
B.Move coordination to an out-of-band channel that was established and tested before the incident.
C.Restrict incident discussions to a distribution list limited to the core response team.
D.Encrypt all incident-related email with the organization's standard message encryption gateway.
AnswerB

If adversaries are inside the environment, any channel they can read or manipulate becomes unsafe for coordination, so the team must fall back to a pre-provisioned out-of-band capability. Pre-establishing and testing it means contact details, credentials, and access methods are already known and will work under pressure, which preserves both the confidentiality of response decisions and the integrity of the coordination process.

Why this answer

When the adversary is positioned to observe the organization's normal communication paths, coordination must shift to a channel the adversary cannot reach. An out-of-band method that was designed, provisioned, and exercised before the incident provides that assurance, keeping containment strategy, evidence handling, and executive decisions confidential while normal platforms are treated as untrusted.

Exam trap

The trap here is believing stronger authentication or tighter distribution lists protect a channel whose contents the attacker can already read.

52
MCQeasy

Which document outlines the overall strategy, roles, and responsibilities for incident response across the organization?

A.Communication plan
B.Incident response plan
C.Incident response policy
D.Incident response playbook
AnswerB

The incident response plan is the governing document defining response strategy, team roles, responsibilities, escalation paths and communication procedures organisation-wide. It provides the overarching framework that individual playbooks and procedures sit beneath, satisfying the requirement for an organisation-level strategy.

Why this answer

The incident response plan (IRP) is the overarching document that defines the organization's strategy, structure, roles, and responsibilities for handling incidents end to end. It establishes who does what across the full lifecycle — preparation, detection, containment, eradication, recovery, and lessons learned. The policy sets intent at a high level, while the plan operationalizes that intent with assigned roles and coordination procedures.

Exam trap

CISM often tests the distinction between policy, plan, and playbook, and candidates frequently select 'policy' because it sounds authoritative, missing that the question asks for strategy plus roles and responsibilities, which is the plan.

How to eliminate wrong answers

Option A is wrong because a communication plan is a subordinate artifact that only addresses who communicates what, to whom, and when — it does not define overall strategy or team roles. Option C is wrong because the incident response policy is a high-level governance statement that mandates the program exists but does not detail roles, responsibilities, or operational strategy. Option D is wrong because a playbook is a tactical, incident-type-specific runbook (e.g., ransomware or phishing) that executes within the broader plan rather than defining it.

53
MCQeasy

What is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

A.To determine if legal action is needed
B.To calculate the financial impact of the incident
C.To assign disciplinary actions
D.To update the incident response plan and procedures
AnswerD

Lessons learned meetings capture what worked and what failed during the incident, then feed those findings back into the incident response plan and procedures. This directly satisfies the stem's requirement for the primary purpose: systematic improvement of future response capability rather than assigning blame or closing tickets.

Why this answer

Lessons learned aims to improve future response by identifying what worked and what didn't.

54
MCQeasy

Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?

A.Incident response plan
B.Incident response policy
C.Incident response playbook
D.Communication templates
AnswerC

An incident response playbook delivers the step-by-step technical instructions the stem demands, mapping specific containment, eradication and recovery actions to a defined incident type. Unlike broader plans or procedures, it prescribes exact commands and decision points, so responders execute consistent, repeatable actions under pressure.

Why this answer

C is correct because an incident response playbook provides detailed, step-by-step technical instructions for handling a specific type of security incident (e.g., ransomware, DDoS, phishing). Unlike the higher-level incident response plan, a playbook contains precise technical actions, such as commands to isolate a host, indicators of compromise (IOCs) to block, and escalation criteria tailored to a particular threat.

Exam trap

The trap here is that candidates confuse the incident response plan (strategic, high-level) with the playbook (tactical, incident-specific), often selecting the plan because it sounds like the most comprehensive document, but the question explicitly asks for 'step-by-step technical instructions' which only the playbook provides.

How to eliminate wrong answers

Option A is wrong because the incident response plan is a strategic document that outlines the overall process, roles, and coordination for incident management, not the granular technical steps for a specific incident type. Option B is wrong because the incident response policy defines high-level management intent, compliance requirements, and governance, not operational technical procedures. Option D is wrong because communication templates provide pre-formatted messages for notifying stakeholders (e.g., legal, PR, customers) but do not contain the technical steps needed to contain, eradicate, or recover from a security incident.

55
MCQmedium

During a P1 incident, the incident response team identifies that the root cause is a misconfigured firewall. According to best practices, which of the following should be the PRIMARY focus of the root cause analysis?

A.Patching the firewall immediately
B.Conducting a lessons learned meeting immediately
C.Determining why the firewall was misconfigured and why the change management process failed
D.Restoring the firewall from backup
AnswerC

Best practise targets the systemic layer: why the misconfiguration occurred and why change management failed to catch it. Fixing only the firewall setting leaves the governance weakness intact, so the same class of error recurs.

Why this answer

Root cause analysis should identify not only the technical cause but also the process and management failures that allowed the misconfiguration to occur.

56
MCQeasy

A security manager is drafting the incident classification criteria for a new incident response plan. Executive leadership has asked how the team will decide, in the first few minutes of an event, whether to invoke the crisis management team. Which of the following is the MOST appropriate basis for that initial escalation decision?

A.The seniority of the person who first reported the event to the service desk
B.The number of alerts the SIEM generated for the affected host in the last 24 hours
C.Whether the affected system is covered by the current cyber insurance policy
D.The predefined severity level assigned to the incident type and its assessed business impact
AnswerD

Severity levels are defined in advance against business impact criteria, so the on-call responder can classify an event consistently within minutes and trigger the agreed escalation path. This removes subjective judgement during the most chaotic phase of an incident and ensures the crisis management team is invoked only when the documented thresholds are met.

Why this answer

Incident classification must be anchored to predefined severity levels that map directly to business impact, so responders can escalate consistently and quickly. This lets the organisation activate the crisis management team at the right threshold without debate, and it aligns response effort with the value at risk rather than with incidental signals such as alert counts or reporter rank.

Exam trap

The trap here is assuming that a dramatic technical signal, such as a high alert count, automatically indicates a high-severity incident requiring executive escalation.

57
Multi-Selecthard

An organisation is defining the criteria its incident response team will use to determine when an incident has been successfully contained and eradication can begin. Which TWO of the following are the MOST appropriate criteria for that decision? (Choose two.)

Select 2 answers
A.The external forensic firm has been formally engaged and has begun its investigation
B.The attacker's command-and-control infrastructure has been sinkholed and no new beaconing is observed from monitored networks
C.All attacker-controlled access paths and persistence mechanisms have been identified and removed
D.The chief information security officer has verbally confirmed to the board that the threat has been neutralised
E.The affected business unit has confirmed that normal transaction volumes have resumed
AnswersB, C

Sinkholing command-and-control and confirming that no hosts continue to beacon provides concrete evidence that the adversary has lost remote control of compromised systems. This is a strong, observable containment indicator because active implants would keep attempting to reach their infrastructure. It directly demonstrates that the attacker's ability to operate within the environment has been disrupted.

Why this answer

Containment is complete when the adversary can no longer operate: every access path and persistence mechanism has been removed, and command-and-control has been disrupted so no implants can receive instructions. These are verifiable technical conditions. Business resumption, executive assurances, and forensic engagement are useful signals or actions but do not prove the threat has been neutralised.

Exam trap

The trap here is accepting restored business operations or executive assurances as proof of containment, when containment is defined by the elimination of the adversary's access and control.

58
MCQmedium

An organization's incident response plan delegates authority to the incident commander to make containment decisions during a severe incident. During an active intrusion affecting multiple business units, the incident commander wants to take a system offline that supports a revenue-generating service. Which factor should PRIMARILY guide this containment decision?

A.The preference of the business unit leader who owns the revenue-generating service
B.Whether the affected system is covered by the organization's cyber insurance policy
C.The technical difficulty of restoring the service after it has been taken offline
D.The potential business impact of the containment action weighed against the risk of continued attacker activity
AnswerD

Containment always involves trade-offs: taking systems offline stops the attacker but may disrupt revenue, while leaving them online preserves service but allows further damage. The incident commander must balance these competing risks using business impact analysis and current threat intelligence. This risk-based judgment, aligned with organizational priorities, is the primary guide. Neither technical feasibility alone nor cost alone captures the full decision, which is fundamentally about acceptable risk.

Why this answer

Containment decisions require weighing the harm of the action against the harm of inaction. Taking a revenue service offline protects the enterprise from further compromise but disrupts business, while leaving it online preserves revenue but risks escalation. The incident commander uses business impact analysis, threat severity, and organizational risk tolerance to strike the right balance.

Restoration difficulty, insurance coverage, and stakeholder preference are secondary inputs, not the primary basis for the decision.

Exam trap

The trap here is letting a single consideration such as restoration effort, insurance, or a business owner's preference drive containment, when the governing criterion is balanced business and threat risk.

59
MCQeasy

During a security incident, the incident response team needs to preserve volatile evidence. Which of the following should be collected first?

A.Files on the hard drive.
B.Network traffic logs.
C.Backup tapes.
D.Contents of RAM.
AnswerD

RAM contains highly volatile data such as running processes, network connections, and encryption keys, which are lost when the system is powered off. Collecting RAM first is critical to preserve this evidence. This follows the order of volatility, a fundamental concept in digital forensics. Failing to capture RAM first could result in loss of crucial evidence for the investigation.

Why this answer

The order of volatility dictates that the most volatile evidence, such as RAM contents, should be collected first because it is lost when the system is powered off or rebooted. Hard drives, logs, and backups are less volatile and can be collected later. This principle ensures that critical evidence is preserved for forensic analysis.

Exam trap

The trap here is assuming that hard drive files are the most critical evidence to collect first, ignoring the rapid loss of volatile memory.

60
MCQmedium

A multinational retailer's security operations center (SOC) identifies that an attacker has compromised a point-of-sale (POS) system in a European store and is moving laterally toward the payment card processing environment. The incident response manager needs to decide the FIRST action to limit business impact while preserving the ability to investigate. Which action should be taken FIRST?

A.Notify the payment card brands and law enforcement before taking any technical action.
B.Isolate the affected POS system from the network using the endpoint detection and response (EDR) tool while keeping it powered on.
C.Immediately power off the compromised POS system and remove it from the network.
D.Delete the malware files from the POS system to stop the attack immediately.
AnswerB

Network isolation via EDR contains the threat by cutting command-and-control and lateral movement paths while preserving volatile memory and running processes for forensic analysis. This balances the twin CISM goals of limiting business impact and maintaining evidence integrity, allowing investigators to collect memory, logs, and network state before any destructive action. It is the least disruptive containment step that still stops the attack from spreading to the payment card environment.

Why this answer

Isolating the endpoint through EDR keeps the system powered on, which preserves volatile evidence while stopping the attacker's ability to move laterally or maintain command and control. This approach satisfies the CISM priority of limiting business impact without compromising the investigation. Notifying external parties or deleting files before containment can let the attack spread and destroy evidence needed for scoping and root cause analysis.

Exam trap

The trap here is assuming that the fastest way to stop an attack is to power off or wipe the infected system, which actually destroys volatile evidence and impedes containment scoping.

61
MCQhard

During a major incident, the incident response team discovers that the attacker is still active in the environment and is moving laterally. The incident response manager must decide on the immediate course of action. Which of the following should be the PRIMARY consideration when determining whether to isolate affected network segments?

A.The attacker's presumed skill level and tools.
B.The cost of replacing the affected network hardware.
C.The number of security staff available to monitor the isolated segments.
D.The potential impact on business operations and critical services.
AnswerD

Isolating network segments can halt the attacker's lateral movement but may also disrupt critical business services, customer-facing systems, and revenue-generating operations. The incident response manager must weigh the security benefit of containment against the business impact, which is a core CISM principle. This decision requires understanding which systems are critical and what tolerances exist for downtime, ensuring the response aligns with organizational risk appetite.

Why this answer

In an active incident with lateral movement, the incident response manager must balance containment against business continuity. The primary consideration is the impact on business operations and critical services, because isolation can disrupt essential functions. This reflects CISM's emphasis on aligning incident response decisions with organizational risk management and business priorities, rather than purely technical or financial factors.

Exam trap

The trap here is focusing on technical or cost factors, such as attacker skill or hardware replacement, instead of the business impact that should drive containment decisions during an active incident.

62
MCQmedium

An organization is developing its incident response plan. The CISO wants to ensure that the plan includes provisions for communicating with external parties during and after an incident. Which of the following should be the PRIMARY consideration when defining external communication procedures?

A.Ensuring that all external communications are approved by the legal department.
B.Using social media to quickly inform the public about the incident.
C.Establishing a single point of contact for all external communications.
D.Aligning communication procedures with legal, regulatory, and contractual requirements.
AnswerD

This is correct because external communications during an incident must comply with laws, regulations, and contracts. For example, data breach notification laws require timely notification to affected parties and regulators. CISM emphasizes that incident response must align with legal and regulatory obligations. This is the primary consideration because failure to comply can result in fines and legal action.

Why this answer

External communication procedures must first ensure compliance with legal, regulatory, and contractual requirements. These obligations dictate who to notify, when, and what information to share. CISM emphasizes that incident response is not just technical but also legal and business-oriented.

While legal approval, a single point of contact, and social media are elements, they are secondary to the primary need to meet compliance obligations and protect the organization.

Exam trap

The trap here is assuming that a single point of contact is the most critical aspect, when actually the primary driver is legal and regulatory compliance.

63
MCQmedium

An information security manager is drafting the incident escalation criteria for the organization's incident response plan. Executive leadership has asked how the team will decide when an incident must be escalated to the crisis management team rather than handled by the technical response team alone. Which of the following is the MOST appropriate basis for defining these escalation thresholds?

A.The number of systems or user accounts confirmed to be affected by the incident
B.The classification of the threat actor, such as nation-state, organized crime, or insider
C.The elapsed time between initial detection and the first containment action taken by the response team
D.The potential or actual business impact of the incident on critical services and objectives
AnswerD

Escalation to the crisis management team exists to mobilize executive decision-making, communications, and resource authority when business objectives or critical services are threatened. Defining thresholds in terms of business impact aligns incident severity with the organization's risk appetite and ensures leadership engages when strategic decisions, regulatory notifications, or customer commitments are at stake.

Why this answer

Escalation criteria should reflect the consequence to the business, because the crisis management team's purpose is to make strategic decisions and commit resources when critical services, regulatory obligations, or stakeholder trust are at risk. Technical metrics such as system counts, response timing, and attribution describe the incident's mechanics or handling rather than its business significance, so they cannot reliably determine when executive engagement is warranted.

Exam trap

The trap here is assuming that escalation is driven by technical size or threat actor prestige, when it is actually driven by business impact and the need for executive decision authority.

64
MCQeasy

An organization's incident response plan includes a communication tree that lists internal contacts and external parties. During a moderate incident, the incident manager must notify the party responsible for making binding decisions about public statements and regulatory disclosures. Which role should be contacted for this purpose?

A.The third-party cloud hosting provider's account manager
B.The legal counsel or chief legal officer
C.The security operations center (SOC) shift lead
D.The IT service desk manager
AnswerB

Legal counsel holds authority over what may be disclosed publicly and what must be reported to regulators, balancing statutory obligations, privilege, and liability. Public statements and regulatory notifications carry legal consequences, so the incident manager must route these decisions through legal. Counsel also determines whether attorney-client privilege should be invoked to protect investigation details from later discovery.

Why this answer

Decisions about public statements and regulatory disclosures require legal authority because they carry statutory, contractual, and liability implications. Legal counsel evaluates notification deadlines, privilege, and the accuracy of messaging. Technical roles supply facts, and vendors supply their own obligations, but neither can authorize the organization's external communications or regulatory filings during an incident.

Exam trap

The trap here is equating technical incident leadership with authority over external communications, when legal counsel owns disclosure decisions.

65
Multi-Selectmedium

An organization is conducting a post-incident review after a major phishing-driven breach. The CISO wants to ensure that lessons learned are captured and translated into measurable improvements. Which TWO of the following activities are MOST important to achieve this objective? (Choose two.)

Select 2 answers
A.Disciplining all employees who clicked the phishing link to reinforce security awareness.
B.Increasing the security budget for the next fiscal year without linking it to specific findings.
C.Immediately deleting all affected mailboxes to remove any remaining malicious content.
D.Assigning corrective actions with owners and due dates based on identified gaps.
E.Documenting root cause, timeline, and response effectiveness in a formal after-action report.
AnswersD, E

Assigning corrective actions with clear owners and due dates converts findings into accountable, trackable improvements. Without ownership and deadlines, lessons learned remain observations rather than changes. This step ensures the post-incident review produces measurable risk reduction and closes the loop on identified weaknesses, which is essential for continuous improvement of the incident response program.

Why this answer

Translating lessons learned into improvement requires both documentation and accountability. A formal after-action report records root cause, timeline, and response effectiveness, while assigning corrective actions with owners and due dates ensures findings are acted upon and tracked. Together they create a measurable, repeatable improvement cycle.

Punitive measures, evidence deletion, or untargeted budget increases do not achieve this objective.

Exam trap

The trap here is equating post-incident activity with punishment or spending, when the real objective is documented findings tied to owned, tracked corrective actions.

66
MCQeasy

A retail company's security operations center receives an alert that a point-of-sale terminal is communicating with a known malicious command-and-control domain. The analyst confirms the connection is active. According to incident response best practices, which action should the analyst take FIRST?

A.Isolate the affected terminal from the network while preserving evidence for investigation
B.Run a full antivirus scan on the terminal and wait for it to complete before taking further action
C.Document the alert details and escalate to management before taking any technical action
D.Immediately power off the terminal to terminate the malicious connection
AnswerA

The immediate priority on confirming active malicious communication is to stop the spread and cut the attacker's control channel. Isolating the terminal halts data exfiltration and lateral movement while keeping the device's state intact for forensic examination. Preserving evidence alongside containment ensures the organization can still determine scope and root cause. This balanced first step protects the business without destroying the information needed to understand the intrusion.

Why this answer

Once malicious command-and-control activity is confirmed, containment is the immediate priority because an active channel enables exfiltration and further intrusion. Isolating the terminal severs that channel without destroying the volatile and stored evidence investigators require. Powering off, scanning in place, or delaying action for documentation all leave the attacker connected or degrade evidence.

The correct sequence is to contain first, then analyze and eradicate, keeping forensic integrity intact throughout.

Exam trap

The trap here is choosing power-off or scanning as the fastest way to stop malware, when those actions either destroy evidence or leave the attacker's channel open.

67
Multi-Selecthard

A financial services firm has just contained a breach in which an attacker exfiltrated customer records from a database server. Legal counsel advises the incident manager that the matter will likely result in litigation and regulatory inquiry. Which TWO actions should the incident manager take to preserve the evidentiary value of the affected server? (Choose two.)

Select 2 answers
A.Allow the database administrator to resume normal backups on the server to maintain recovery capability.
B.Delete the attacker's malware binaries to prevent accidental execution during the investigation.
C.Capture a forensic image of the server's volatile memory and disk before any remediation or reboot occurs.
D.Rebuild the server from a known-good image immediately to restore service and eliminate attacker persistence.
E.Document the chain of custody for all collected evidence, recording who handled it, when, and for what purpose.
AnswersC, E

Order of volatility dictates that memory contents, running processes, network connections, and encryption keys are lost on shutdown or reboot. Capturing a forensic image of both RAM and disk preserves the most perishable evidence first, maintaining the chain of custody and enabling later analysis. Without this step, critical artifacts such as active sessions and injected code may be permanently destroyed before remediation begins.

Why this answer

Preserving evidence in a matter destined for litigation and regulatory scrutiny requires capturing volatile and non-volatile data before any remediation and maintaining rigorous chain-of-custody records. These two actions protect admissibility and demonstrate due diligence. Rebuilding the server, deleting malware, or resuming backups would overwrite or destroy artifacts, weakening both the legal case and the organization's regulatory defensibility.

Exam trap

The trap here is prioritizing rapid service restoration over evidence preservation, when in litigation-bound incidents the order of volatility and chain of custody must come first.

68
MCQeasy

A company's incident response plan defines roles for the incident response team, but during a recent tabletop exercise it became clear that no one had authority to make binding decisions about shutting down production systems. Which of the following should be established to resolve this gap?

A.A service level agreement with the managed security service provider guaranteeing faster response.
B.An increase in the security operations centre's monitoring coverage and alert thresholds.
C.A more detailed technical runbook describing how to shut down each production system.
D.A documented decision-making authority and escalation path approved by executive management.
AnswerD

The gap is governance, not technology. Someone must hold pre-delegated authority to make high-impact calls such as taking production offline, and that authority must be documented and endorsed by executives so it is recognized during a crisis. A clear escalation path also tells responders whom to wake at 3 a.m. and who owns the final call when business and security priorities conflict.

Why this answer

Incident response authority is a governance matter that must be defined before a crisis. Documenting who may authorize disruptive actions, and how disagreements escalate, gives responders clear decision rights approved at the executive level. Without it, even well-detected incidents stall while teams wait for permission, and the organization loses the time that containment depends on.

Exam trap

The trap here is responding to a missing-authority finding with more technical procedures or monitoring instead of a governance decision about who may act.

69
MCQhard

Following a ransomware incident where data was encrypted and exfiltrated, the root cause analysis reveals that the initial access occurred through a phishing email that bypassed email filters due to a misconfiguration. The misconfiguration was not identified because the security team lacked a formal process to review firewall rule changes. Which of the following is the most appropriate management/governance failure to document in the lessons learned?

A.Employees should have been trained to recognize phishing emails.
B.The email filter vendor did not provide adequate support.
C.The security team did not have a change management process for security control configurations.
D.The incident response plan was not followed during the incident.
AnswerC

The root cause is a governance gap: no change management process governed security control configuration changes, so the email filter misconfiguration went unreviewed. Documenting this management failure addresses the underlying control weakness rather than the phishing symptom.

Why this answer

The technical cause is the phishing email, the process failure is the lack of review of email filter configurations, and the management/governance failure is the absence of a change management process for security controls.

70
MCQhard

An organization is engaging an external forensics firm to investigate a suspected data breach. Which of the following is the most important step to ensure that evidence remains admissible in legal proceedings?

A.Ensuring the forensics firm has signed a non-disclosure agreement
B.Negotiating a fixed price for the investigation
C.Requiring the forensics firm to report findings directly to the CEO
D.Issuing a legal hold and making forensic copies of affected systems before remediation
AnswerD

Issuing a legal hold preserves potentially relevant data and suspends routine deletion, while forensic copies capture the affected systems' state before remediation alters or destroys artefacts. This satisfies the admissibility constraint by maintaining an unbroken chain of custody and preserving original evidence for legal proceedings.

Why this answer

Preserving the chain of custody and ensuring forensic copies are made before remediation is critical for evidence admissibility. Legal hold ensures that relevant data is preserved.

71
MCQhard

A multinational organisation suffers a breach affecting customers in several jurisdictions. The incident response manager must coordinate notification obligations while the investigation is still ongoing and facts are incomplete. Which of the following is the MOST appropriate approach?

A.Engage legal counsel to map jurisdictional notification requirements and issue notices as facts are confirmed, meeting each deadline
B.Delegate all notification decisions to the public relations team to ensure consistent messaging across markets
C.Notify every customer in all markets immediately, regardless of whether their data was affected
D.Wait until the investigation is fully complete so that a single, comprehensive notification can be issued to all affected parties
AnswerA

Notification duties vary by jurisdiction in scope, timing, and recipients, so legal expertise is essential to map them accurately. Issuing notices progressively as facts are confirmed satisfies statutory deadlines while avoiding premature or inaccurate disclosures. This approach balances regulatory compliance, customer transparency, and the practical reality that breach investigations evolve over time.

Why this answer

Cross-border breaches trigger overlapping notification regimes with different thresholds, recipients, and deadlines. Legal counsel must map those obligations, and notices should be issued progressively as facts are confirmed so each jurisdiction's deadline is met without publishing inaccurate information. This balances compliance with the reality of an incomplete investigation.

Exam trap

The trap here is believing that a breach should be fully investigated before any notification is made, when statutory clocks often start at the moment of awareness.

72
MCQmedium

A security operations centre (SOC) analyst receives an alert that a production database server is transmitting large volumes of customer data to an external IP address. The analyst confirms the traffic is malicious. According to CISM best practices, which of the following should the analyst do FIRST?

A.Isolate the database server from the network to contain the data exfiltration.
B.Review firewall and proxy logs to determine the full scope of the exfiltration.
C.Notify the chief information security officer (CISO) and legal counsel of the suspected breach.
D.Capture a full memory image of the database server before taking any other action.
AnswerA

Containment is the immediate priority once an incident is confirmed, because ongoing exfiltration causes continuous business and regulatory harm. Isolating the server stops the loss of customer data while preserving the system state for later forensic analysis and eradication. This aligns with the incident response lifecycle, where containment follows detection and precedes recovery. Delaying containment to gather more information or notify stakeholders allows the attacker to continue extracting data.

Why this answer

Once an analyst validates that malicious exfiltration is occurring, the immediate priority is to stop the loss of business data. Containment, such as isolating the affected server, halts the ongoing damage while preserving the environment for investigation. Notification, deep forensic imaging, and broad log review are all necessary activities, but they follow or accompany containment rather than preceding it, because every minute of delay increases data loss and regulatory exposure.

Exam trap

The trap here is assuming that forensic preservation or executive notification must happen before any containment action, when in fact stopping active data loss takes precedence.

73
MCQhard

A security analyst discovers that an employee's credentials were used to access a sensitive database containing customer PII. The analyst immediately disables the account and begins remediation. Which incident category best describes this scenario?

A.Data breach
B.Physical security
C.Account compromise
D.Insider threat
AnswerC

Using an employee's credentials to reach customer PII constitutes account compromise: an attacker gained unauthorised access through a legitimate identity rather than malware or a network breach. Disabling the account and remediating addresses the compromised credential itself, confirming this category fits the scenario.

Why this answer

The incident involves unauthorized use of legitimate credentials to access a sensitive database, which is the defining characteristic of an account compromise. The immediate disabling of the account and remediation aligns with standard incident response procedures for credential theft, where the attacker has gained authenticated access without authorization. This is distinct from a data breach, which focuses on the exfiltration or exposure of data, not the method of access.

Exam trap

The trap here is that candidates confuse the method of access (account compromise) with the outcome (data breach), but CISM distinguishes incidents by the root cause and attack vector, not just the potential impact.

How to eliminate wrong answers

Option A is wrong because a data breach specifically refers to the confirmed exfiltration, loss, or unauthorized disclosure of data, whereas this scenario only describes unauthorized access using compromised credentials—data may not have been extracted or exposed. Option B is wrong because physical security incidents involve tangible assets like unauthorized entry to a facility, theft of hardware, or tampering with physical controls, not the use of digital credentials to access a database. Option D is wrong because an insider threat requires the actor to be an employee, contractor, or trusted party with legitimate access who intentionally or negligently causes harm, but this scenario does not specify the identity of the attacker—it could be an external threat actor using stolen credentials.

74
MCQmedium

An organization has completed its response to a data breach and is conducting a post-incident review. Management wants assurance that lessons learned will actually improve future response capability. Which outcome BEST demonstrates that the post-incident review achieved this objective?

A.A detailed timeline of the incident is distributed to all employees as a training awareness bulletin.
B.The final incident report is archived in the document management system for future reference.
C.The incident response plan is updated with assigned corrective actions, owners, and due dates tracked to closure.
D.The incident response team receives a summary presentation highlighting the attacker's tactics and techniques.
AnswerC

The definitive sign that lessons learned will improve capability is that findings are converted into documented corrective actions with accountable owners and deadlines, then tracked to completion. This closes the loop between analysis and change, ensuring gaps in detection, escalation, or containment are remediated. Tracking to closure also gives management measurable assurance rather than a one-time report.

Why this answer

Post-incident reviews only improve capability when findings become tracked corrective actions with named owners and deadlines. This converts analysis into verified changes to plans, controls, and training, and provides management with evidence that gaps have been addressed. Distributing timelines, giving briefings, or archiving reports may support the process but do not by themselves change future response outcomes.

Exam trap

The trap here is mistaking communication of findings for remediation of findings, when the review's objective is verified corrective action.

75
MCQhard

During a forensic investigation, the external forensics firm discovers evidence that may indicate criminal activity. The incident manager wants to ensure attorney-client privilege is maintained. What should be done?

A.Share evidence directly with law enforcement
B.Involve legal counsel to manage privilege
C.Ignore privilege to speed up investigation
D.Publicly disclose the evidence
AnswerB

Involving legal counsel preserves attorney-client privilege by channelling forensic findings through the legal team, since privilege attaches to communications made for legal advice. This satisfies the incident manager's constraint: counsel directs the investigation, and work product produced under their direction remains protected from disclosure during any subsequent criminal proceedings.

Why this answer

Involving legal counsel is essential to establish and preserve attorney-client privilege over the forensic investigation. Legal counsel can direct the scope of the investigation, issue a 'Kovel letter' to engage the external forensics firm as an agent of the attorney, and ensure that all communications and findings are protected under the work-product doctrine. Without this step, any evidence of criminal activity could be deemed discoverable and waive privilege, potentially compromising the organization's legal defense.

Exam trap

CISM often tests the misconception that speed or direct law enforcement cooperation is the priority, but the trap here is that preserving attorney-client privilege requires legal counsel to be involved from the outset, not after evidence is already shared.

How to eliminate wrong answers

Option A is wrong because sharing evidence directly with law enforcement without legal counsel's review typically waives attorney-client privilege and may violate data privacy regulations (e.g., GDPR, HIPAA) by prematurely disclosing protected information. Option C is wrong because ignoring privilege to speed up the investigation destroys the legal protection of the entire forensic work product, making all findings admissible in court against the organization and exposing it to liability. Option D is wrong because publicly disclosing evidence of criminal activity not only waives privilege but also violates confidentiality agreements, damages reputation, and may obstruct justice by tipping off suspects.

Page 1 of 3 · 190 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Incident Management questions.