Courseiva

CCNA Incident Management Questions

75 of 190 questions · Page 2/3 · Incident Management · Answers revealed

76
MCQmedium

An organization has just experienced a P1 incident. Which of the following communication steps should occur FIRST?

A.Inform customers
B.Notify law enforcement
C.Issue a media statement
D.Notify executive leadership
AnswerD

Notifying executive leadership first satisfies the P1 escalation requirement, ensuring senior management can authorise crisis resources and fulfil governance duties. Executives need immediate awareness to make strategic decisions, manage regulatory exposure and coordinate external messaging, whereas technical containment proceeds in parallel. This aligns with incident response escalation protocols prioritising executive notification for critical incidents.

Why this answer

For a P1 (highest severity) incident, the first communication step is to notify executive leadership so they can authorize resources, make business decisions, and activate the crisis management structure. Executives own the risk and must be informed before any external messaging occurs. Customer, legal, and media communications follow only after leadership is briefed and the facts are established.

Exam trap

CISM often tests the ordering of incident communications, and candidates frequently pick customer or media notification because it feels urgent, missing that executive leadership must be briefed first to authorize and coordinate all external messaging.

How to eliminate wrong answers

Option A is wrong because informing customers before leadership has assessed the situation can cause premature, inaccurate disclosure and legal exposure. Option B is wrong because law enforcement notification is a legal/regulatory decision made after leadership and legal counsel assess whether the incident meets reporting thresholds. Option C is wrong because issuing a media statement is a downstream step handled by communications under leadership direction, not the first action.

77
Multi-Selecteasy

Which THREE of the following are typical roles in an incident response team?

Select 3 answers
A.Human resources manager
B.Security analyst
C.Chief executive officer (CEO)
D.Forensic investigator
E.Legal counsel
AnswersB, D, E

The security analyst is a core incident response team role, performing detection, triage and initial containment of the event. This hands-on technical function is consistently listed alongside incident lead, forensics and communications roles in typical CISM team structures.

Why this answer

Security analyst (B) is a core incident response role, responsible for monitoring alerts, triaging events, and performing initial containment and eradication actions. Forensic investigator (D) is also typical, handling evidence acquisition and analysis using tools like memory and disk imaging while preserving chain of custody. Legal counsel (E) is a standard member because incidents often trigger breach-notification laws, regulatory reporting, and liability concerns that must be managed during response.

Human resources manager (A) and CEO (C) may be consulted or informed, but they are not typical hands-on incident response team roles, so they are not correct here.

Exam trap

CISM often tests the difference between standing IR team roles and situationally activated stakeholders, and candidates frequently include HR or the CEO because they appear in incident scenarios without being core team members.

78
MCQmedium

During a major incident, the crisis management team (CMT) has been activated. Which of the following is typically NOT a member of the CMT?

A.Security analyst
B.General counsel
C.Chief information security officer
D.CEO
AnswerA

A security analyst performs hands-on triage and evidence collection, an operational role rather than a strategic one. The CMT comprises decision-makers such as the CISO, legal counsel, communications and business leaders who authorise response and manage enterprise impact, so the analyst supports the team rather than sitting on it.

Why this answer

The CMT includes senior executives like CEO, CFO, CISO, GC, and Communications; a security analyst is part of the incident response team, not the CMT.

79
MCQmedium

A retail company suffers a breach involving payment card data. The incident response manager must decide whether to engage external forensic investigators and outside counsel. Which of the following is the PRIMARY reason to bring in external expertise at this point?

A.External investigators will assume legal liability for the breach and shield the company from regulatory penalties.
B.External investigators are required by the payment card industry to be used for all card data breaches.
C.External investigators provide independent expertise and objective findings that support legal and regulatory obligations.
D.External investigators allow the internal security team to avoid documenting the incident in the ticketing system.
AnswerC

A major breach demands skills, surge capacity, and objectivity that most internal teams cannot sustain while also running day-to-day security. External investigators bring specialized tooling and prior case experience, and their independent findings carry more weight with regulators, courts, card brands, and insurers. Engaging outside counsel also helps structure the work under privilege, protecting sensitive analysis from later disclosure.

Why this answer

Complex breaches exceed typical internal capacity and require independence, specialized forensics, and legal structuring. External investigators deliver objective findings that stand up to regulator, insurer, and court scrutiny, while outside counsel can direct the work under privilege. This combination supports both accurate root-cause determination and the organization's legal and contractual obligations.

Exam trap

The trap here is treating external forensics as a way to transfer liability or as a blanket regulatory mandate instead of a source of independent expertise and defensible findings.

80
MCQhard

A company experiences a DDoS attack that overwhelms its internet-facing services. The incident response team implements mitigation measures. During which phase of incident response is it most appropriate to collect and preserve evidence for potential legal action?

A.During containment, eradication, and recovery
B.During preparation
C.During detection and analysis
D.During post-incident activity
AnswerA

Evidence collection belongs to the containment, eradication, and recovery phase, where volatile data such as memory, logs, and network captures must be preserved before systems are rebuilt or wiped. This satisfies the stem's legal-action constraint, since forensic artefacts degrade or vanish once recovery overwrites affected hosts.

Why this answer

Evidence collection and preservation must begin the moment an incident is confirmed and continue through containment, eradication, and recovery, because volatile data such as memory, running processes, and network connections can be destroyed by the very actions taken to stop the attack. NIST SP 800-61 explicitly places evidence gathering within these handling phases, not only after the fact. Waiting until post-incident activity risks losing forensic artifacts needed for legal action, root-cause analysis, or law enforcement referral.

Exam trap

The trap here is assuming evidence collection is a distinct, later phase (post-incident) rather than an activity that must be woven into containment, eradication, and recovery — CISM candidates frequently pick 'post-incident activity' because it sounds like the formal reporting stage.

How to eliminate wrong answers

Option B is wrong because preparation is about building the capability — policies, tools, training, and jump bags — before any incident occurs; there is no live evidence to collect yet. Option C is wrong because detection and analysis is where the incident is identified and scoped; while some initial triage data may be captured, the formal, legally defensible preservation effort spans the subsequent handling phases. Option D is wrong because post-incident activity is about lessons learned and report finalization; by then, volatile evidence is long gone and only retained artifacts remain.

81
MCQmedium

After a DDoS attack, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). According to best practices, what should happen next?

A.Notify customers and shut down operations.
B.Escalate to the business continuity and disaster recovery teams.
C.Continue current response efforts and hope for the best.
D.Declare the incident as a disaster immediately without further analysis.
AnswerB

When recovery cannot be achieved within the maximum tolerable downtime, the incident exceeds incident management's remit and threatens critical service delivery. Escalating to business continuity and disaster recovery teams activates alternate recovery strategies, restoring operations within acceptable timeframes as best practise dictates.

Why this answer

If MTD cannot be met, business continuity or disaster recovery plans should be activated.

82
Multi-Selecthard

A CISO at a healthcare payer is revising the incident response plan after a tabletop exercise exposed confusion about who may commit the organization to public statements and remediation costs during a major breach. The board wants clarity on governance-level decision rights that must exist before the next incident. Which TWO activities should be assigned to the crisis management team rather than to the tactical incident response team? (Choose two.)

Select 2 answers
A.Isolating affected network segments and collecting volatile memory from compromised hosts
B.Authorizing external legal counsel engagement and regulatory disclosure strategy
C.Tuning SIEM correlation rules to reduce false positives from the newly deployed endpoint agent
D.Approving business continuity activation and prioritization of critical claims-processing systems
E.Updating the incident ticketing system with containment timestamps for each affected host
AnswersB, D

Decisions about engaging outside counsel, invoking privilege, and timing regulatory notification carry enterprise legal and reputational consequences that exceed the tactical team's remit. The crisis management team is chartered to make these governance-level calls because they affect the whole organization, require executive authority, and often involve the board. Tactical responders supply technical facts, but the authority to commit the enterprise to a disclosure position belongs at this strategic layer.

Why this answer

The crisis management team exists to make strategic, enterprise-wide decisions that tactical responders lack the authority to make. Authorizing legal counsel and disclosure strategy commits the organization externally, while approving continuity activation and recovery prioritization allocates business resources across functions. Both require executive judgment about legal exposure, reputation, and operational trade-offs.

Host forensics, SIEM tuning, and ticket logging are operational execution tasks that remain with the tactical incident response and security operations teams.

Exam trap

The trap here is assuming any activity performed during a major incident belongs to the crisis management team, when tactical containment, detection tuning, and documentation stay with the incident response team.

83
MCQhard

A security manager is reviewing the incident response plan and notices that the plan does not specify how to handle a situation where the incident response team cannot reach the primary incident response manager. What should be done to address this gap?

A.Outsource incident response management to a third-party provider.
B.Implement a policy that the incident response manager must always be available.
C.Require all incident response team members to report to the CISO in the absence of the manager.
D.Designate an alternate incident response manager and include contact information in the plan.
AnswerD

Including an alternate incident response manager ensures continuity of leadership if the primary is unavailable. This is a critical component of incident response planning, as it prevents delays in decision-making during a crisis. The alternate should have the same authority and training as the primary. This addresses the gap directly and is a best practice for business continuity and incident management.

Why this answer

The most effective way to address the lack of a backup for the incident response manager is to designate an alternate and include their contact details in the plan. This ensures that leadership is maintained even if the primary manager is unavailable. It is a simple, cost-effective, and standard practice in incident response planning, aligning with CISM's emphasis on preparedness and resilience.

Exam trap

The trap here is thinking that escalation to a higher authority or outsourcing solves the problem, when the core issue is lack of a designated alternate.

84
MCQmedium

An organisation has just completed containment of a significant data breach. The incident response manager is preparing the post-incident review. Which of the following activities BEST ensures that lessons learned translate into lasting improvement of the incident response capability?

A.Circulating the final incident report to all staff so everyone is aware of what happened
B.Updating the risk register to reflect the incident and then archiving the incident documentation
C.Assigning each corrective action to an accountable owner with a due date and tracking it to closure
D.Conducting a tabletop exercise on the same scenario within the following week
AnswerC

Lasting improvement requires converting findings into owned, time-bound actions that are tracked until verified complete. This creates accountability and makes gaps visible to management. Tracking to closure also provides evidence for auditors and regulators that the organisation acted on the incident rather than merely documenting it, which is the essence of an effective lessons-learned process.

Why this answer

The purpose of a post-incident review is to convert findings into verified improvements. Assigning each corrective action to a named owner with a deadline and tracking it to closure provides the accountability and visibility that turn recommendations into real capability gains, and it produces evidence that management acted on the lessons identified.

Exam trap

The trap here is equating communication of lessons learned, such as distributing a report, with actually implementing and verifying the resulting improvements.

85
Multi-Selecteasy

An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)

Select 2 answers
A.Ransomware
B.Password expiration
C.Data breach
D.Software update failure
E.Phishing simulation
AnswersA, C

Ransomware demands a dedicated playbook because its encryption, extortion and recovery steps differ fundamentally from other incidents. A predefined sequence covering isolation, backup validation, decryption decisions and ransom policy enables rapid, consistent containment, matching the stem's call for playbooks tailored to distinct incident types.

Why this answer

A dedicated playbook is warranted for ransomware (A) because it requires a specific, time-critical sequence of containment, isolation of encrypted hosts, identification of the ransomware strain, and recovery from known-good backups to avoid paying the ransom. A dedicated playbook is also warranted for a data breach (C) because it triggers distinct legal, regulatory, and forensic obligations such as breach notification timelines, evidence preservation, and coordination with counsel and regulators. Password expiration (B) is a routine, scheduled identity-management task handled by normal operational procedures, not an incident response playbook.

Software update failure (D) is a change/problem management issue resolved through rollback or patch remediation rather than incident response. Phishing simulation (E) is a proactive security-awareness exercise, not an actual incident, so it does not require an incident response playbook.

86
Multi-Selectmedium

An organization is developing its incident response capabilities and wants to ensure that it can effectively detect and respond to security incidents. Which TWO of the following are essential components of an incident response programme that should be established before an incident occurs? (Choose two.)

Select 2 answers
A.A disaster recovery plan.
B.Incident response policy and procedures.
C.A list of all IT assets and their locations.
D.A vulnerability management programme.
E.A communication plan with internal and external stakeholders.
AnswersB, E

An incident response policy provides the mandate and framework for the programme, while procedures detail the steps to follow during an incident. These documents ensure consistent and effective response, define roles and responsibilities, and align with business objectives. Without them, response efforts may be ad hoc and inefficient. They are foundational components that must be established before an incident occurs.

Why this answer

The essential components of an incident response programme include an incident response policy and procedures, which provide the framework and steps for handling incidents, and a communication plan, which ensures effective information sharing with stakeholders. These are directly related to the response process and are necessary for a coordinated and effective response.

Exam trap

The trap here is confusing broader security or IT plans, such as asset inventory or disaster recovery, with the core components of an incident response programme.

87
MCQmedium

Which of the following is the primary purpose of conducting a root cause analysis (RCA) after a security incident?

A.To identify the technical vulnerability that was exploited
B.To determine process and governance failures that allowed the incident to occur
C.To satisfy regulatory reporting requirements
D.To assign blame to responsible individuals
AnswerB

RCA examines the underlying process and governance failures that permitted the incident, not merely the technical trigger. This satisfies the stem's demand for the primary purpose: preventing recurrence by correcting systemic weaknesses in controls, oversight and decision-making, rather than attributing blame or documenting the event itself.

Why this answer

RCA aims to identify underlying causes to prevent recurrence. While it may involve understanding the technical cause, the ultimate goal is to improve processes and controls.

88
MCQeasy

Which incident category involves unauthorized access to systems or data by an individual within the organization?

A.DDoS
B.Data breach
C.Ransomware
D.Insider threat
AnswerD

Insider threat covers misuse by employees, contractors or partners holding legitimate access, so it directly satisfies the stem's requirement that the actor be an individual within the organization. Unlike external attacks, the access is authorised initially, making detection harder and distinguishing it from other incident categories.

Why this answer

Insider threat incidents are caused by employees, contractors, or other trusted insiders.

89
MCQeasy

Which incident severity level requires executive notification and a 24/7 response?

A.P2 — High
B.P3 — Medium
C.P1 — Critical
D.P4 — Low
AnswerC

P1 Critical denotes the highest severity, where business-critical systems or data are affected, so the plan mandates immediate round-the-clock response and escalation to executives. This satisfies the stem's requirement linking executive notification with continuous 24/7 response.

Why this answer

P1 (critical) incidents have major business impact and require immediate executive notification and round-the-clock response.

90
MCQhard

Following a major security incident, the lessons learned meeting is scheduled. Which of the following outcomes is MOST important to ensure the effectiveness of future incident response?

A.Conducting a new risk assessment
B.Creating a detailed report for senior management
C.Updating the incident response plan and playbooks based on findings
D.Assigning blame to responsible parties
AnswerC

Updating plans and playbooks converts lessons-learned findings into revised procedures, directly satisfying the stem's requirement for effective future incident response. Unlike awareness or reporting changes, this closes the loop by embedding corrective actions into documented, repeatable steps responders follow under pressure, ensuring the same failures are not repeated.

Why this answer

The primary outcome of a lessons learned meeting is to identify improvements and update the IR plan, not just document or blame.

91
MCQmedium

A financial services firm's incident response team has contained a credential-stuffing attack that compromised several customer accounts. The CISO asks the incident manager to determine what should happen next before the team stands down. Which action BEST aligns with CISM incident management practices?

A.Conduct a post-incident review to capture lessons learned and update controls and the response plan.
B.Reimage all customer account systems and rotate every credential in the environment without further analysis.
C.Escalate the incident to law enforcement and suspend all customer-facing services pending investigation.
D.Immediately close the incident ticket and release the response team so normal operations can resume.
AnswerA

After containment, eradication, and recovery, CISM emphasizes performing a post-incident review to identify root causes, evaluate the effectiveness of the response, and feed improvements back into the incident response plan and security controls. This is the correct next step because it transforms the incident into actionable organizational learning rather than simply returning to a normal state without any improvement.

Why this answer

The post-incident review is a core CISM activity that converts a contained incident into organizational improvement. It examines root cause, response effectiveness, and gaps, then updates the incident response plan and controls. Simply closing the ticket, over-escalating, or blindly reimaging systems skips the analysis needed to prevent recurrence and strengthen the security program.

Exam trap

The trap here is assuming the incident ends at containment, when CISM expects a formal post-incident review to drive improvements.

92
MCQmedium

During a data breach investigation, the incident response team discovers that a backup was encrypted by ransomware. The team needs to determine the sequence of events leading to the encryption. Which of the following documentation is MOST critical to preserve for potential litigation?

A.The communication logs between team members
B.The chain of custody for the backup media
C.The forensic tools used in the investigation
D.The incident response plan version used during the incident
AnswerB

Chain of custody documentation records who handled the backup media, when, and how, proving evidence integrity. Without it, encrypted media may be ruled inadmissible, undermining litigation. It directly satisfies the stem's requirement to preserve documentation critical for potential legal proceedings.

Why this answer

Chain of custody documentation is essential to prove the integrity and admissibility of digital evidence in court.

93
MCQeasy

In the incident response team structure, who is typically responsible for coordinating communication with external stakeholders such as customers and the media?

A.Legal counsel
B.Communications lead
C.Incident response manager
D.Executive sponsor
AnswerB

The communications lead owns external messaging, translating technical incident details into statements for customers, regulators and the media. This satisfies the stem's coordination constraint by centralising stakeholder communication, preventing engineers or executives from issuing conflicting accounts. Unlike the incident commander, who directs containment and recovery, this role carries no operational authority over remediation.

Why this answer

The communications lead handles external messaging to ensure consistency and accuracy.

94
MCQeasy

Which component of an incident response program is most likely to include step-by-step technical actions for addressing a specific type of security incident?

A.Incident response playbook
B.Communication templates
C.Incident response policy
D.Incident response plan
AnswerA

A playbook provides prescriptive, step-by-step technical procedures for a specific incident type, such as ransomware or phishing. This contrasts with the broader incident response plan, which sets policy, roles and lifecycle phases rather than granular remediation actions.

Why this answer

An incident response playbook provides detailed, step-by-step technical procedures for handling specific incident types (e.g., ransomware, DDoS, phishing). Unlike higher-level documents, playbooks contain actionable commands, tool-specific instructions, and decision trees that guide responders through containment, eradication, and recovery. This granularity ensures consistent and efficient execution during an active security event.

Exam trap

ISACA CISM often tests the distinction between a plan (strategic, high-level) and a playbook (tactical, step-by-step), causing candidates to mistakenly choose the incident response plan because it sounds more comprehensive.

How to eliminate wrong answers

Option B (Communication templates) is wrong because they focus on predefined messaging for stakeholders (e.g., customers, regulators), not on technical remediation steps. Option C (Incident response policy) is wrong because it defines high-level governance, roles, and compliance requirements, not the tactical actions for a specific incident type. Option D (Incident response plan) is wrong because it outlines the overall organizational approach, escalation paths, and coordination procedures, but lacks the detailed, incident-specific technical steps found in a playbook.

95
MCQmedium

An organization is updating its incident response plan after a major incident. Which post-incident activity should be performed to ensure the plan reflects lessons learned?

A.Updating the IR plan and playbooks based on lessons learned
B.Sharing indicators of compromise with an ISAC
C.Revising the IR policy
D.Conducting a tabletop exercise
AnswerA

Updating the IR plan and playbooks translates lessons learned into revised procedures, contacts and decision criteria, ensuring the next response benefits from the post-incident review. This satisfies the stem's requirement directly, since documentation changes are the mechanism by which findings actually alter future incident handling.

Why this answer

Updating the IR plan and playbooks based on lessons learned is the definitive post-incident activity that directly incorporates findings from the after-action review into the operational documentation. This ensures the plan reflects actual gaps or improvements identified during the incident, making it actionable for future events. Without this update, the plan remains static and fails to evolve with the organization's threat landscape.

Exam trap

The trap here is that candidates confuse 'revising the IR policy' (a high-level governance document) with 'updating the IR plan and playbooks' (the operational, detailed documentation that directly incorporates lessons learned), leading them to choose the broader, less actionable option.

How to eliminate wrong answers

Option B is wrong because sharing indicators of compromise with an ISAC is a threat intelligence sharing activity that supports broader community defense, not a post-incident activity to update the organization's own IR plan. Option C is wrong because revising the IR policy is a higher-level governance change that typically occurs less frequently and is not the immediate step for capturing specific operational lessons learned from a single incident. Option D is wrong because conducting a tabletop exercise is a proactive testing activity used to validate the plan, not a post-incident activity to document and apply lessons learned from a real incident.

96
MCQeasy

Which component of an incident response programme provides detailed step-by-step instructions for handling a specific type of incident?

A.Incident response playbook
B.Incident response policy
C.Incident response plan
D.Communication templates
AnswerA

Playbooks translate the incident response plan into documented, step-by-step procedures for a specific incident category, such as ransomware or data breach. This granular, scenario-specific detail is precisely what the stem requests, distinguishing playbooks from broader plans, policies and general procedures.

Why this answer

Playbooks are specific to incident types (e.g., ransomware) and provide step-by-step guidance, whereas the IR plan is a high-level document and policy sets overall intent.

97
MCQhard

During a major incident, the incident response team has contained the threat but recovery is taking longer than expected. The business continuity manager reports that the manual workaround in place will fail within four hours due to capacity limits. Which action should the incident manager take FIRST?

A.Instruct the business continuity manager to extend the manual workaround beyond its documented capacity limits.
B.Direct the recovery team to work overtime and compress testing steps to accelerate system restoration.
C.Suspend incident communications until the recovery team confirms a new restoration estimate.
D.Escalate the recovery timeline risk to the crisis management team (CMT) so it can decide on activating the business continuity plan.
AnswerD

When containment is achieved but recovery threatens to exceed the tolerance of manual workarounds, the decision to invoke the business continuity plan involves enterprise trade-offs beyond the incident response team's authority. Escalating to the CMT ensures executives can authorize alternate processing sites, customer communications, or resource commitments before the workaround fails, preventing an avoidable operational outage.

Why this answer

Containment success does not end the incident if recovery cannot be completed within the tolerance of interim workarounds. The imminent failure of the manual workaround is a business continuity trigger that exceeds the incident response team's authority. Escalating to the CMT enables executives to authorize continuity plan activation, alternate processing, and stakeholder communications before the workaround collapses.

Exam trap

The trap here is treating containment as the end of the incident manager's decision scope, when recovery risk crossing business tolerance requires executive escalation.

98
MCQeasy

An organization is defining the composition of its incident response team. Which role is PRIMARILY responsible for coordinating communication with the media and the public during a high-profile incident?

A.The public relations or communications lead.
B.The legal counsel.
C.The IT operations director.
D.The incident response manager.
AnswerA

The communications lead owns the organization's external messaging, including media statements, public disclosures, and stakeholder updates. During a high-profile incident, this role works with legal, executive leadership, and the incident response manager to ensure accurate, consistent, and timely communication while protecting the organization's reputation and meeting disclosure obligations.

Why this answer

External communication during a high-profile incident belongs to a designated communications or public relations lead who can align messaging with legal requirements and executive direction. This separation keeps technical responders focused on containment and recovery while ensuring the organization speaks with one consistent voice. Legal counsel reviews for risk, and the incident response manager supplies accurate technical context, but neither owns the media and public communication role.

Exam trap

The trap here is assuming the incident response manager or legal counsel handles all incident communication, when external media and public messaging is a distinct communications function.

99
MCQmedium

A security manager is drafting the incident response plan and must specify how the organization will communicate with regulators, law enforcement, and the media during a high-severity breach. The chief information security officer (CISO) wants to ensure that all external communications are coordinated, legally defensible, and consistent. Which of the following should the CISO require FIRST to meet this objective?

A.Require all external communications to be handled exclusively by the legal department without input from security or communications staff.
B.Designate a single, pre-authorized spokesperson and require all external communications to flow through a defined approval chain.
C.Publish the full incident response plan on the corporate intranet so all employees understand the communication process.
D.Grant every member of the incident response team authority to speak with external parties to speed up information sharing.
AnswerB

A single pre-authorized spokesperson with a defined approval chain ensures consistent, legally reviewed messaging and prevents conflicting statements to regulators, law enforcement, and media. This directly addresses the CISO's need for coordinated and defensible external communications before, during, and after a high-severity breach, and it aligns with CISM guidance on incident communication roles and escalation paths.

Why this answer

Coordinated external communication during a high-severity breach requires a single pre-authorized spokesperson and a defined approval chain. This ensures messages to regulators, law enforcement, and media are consistent, legally reviewed, and technically accurate. Empowering everyone to speak or relying solely on one department creates confusion, legal exposure, and inconsistent messaging that can worsen the incident's impact.

Exam trap

The trap here is assuming that faster, decentralized communication is always better, when uncontrolled external statements during a breach often create legal and reputational harm.

100
MCQmedium

During a P1 (critical) incident involving a ransomware attack that has encrypted critical systems, the incident manager needs to provide updates to executives. What is the recommended frequency for situation reports (sitreps)?

A.Hourly
B.Only at milestone events
C.Every 4 hours
D.Daily
AnswerA

Hourly sitreps match the tempo a P1 ransomware crisis demands, where encryption spreads and containment decisions change rapidly. Executives need current impact and recovery status to authorise escalation and communications, so a fixed hourly cadence prevents stale information during the critical early containment window.

Why this answer

For P1 incidents, hourly sitreps keep executives informed of rapidly evolving situations.

101
MCQhard

An organization has experienced a data breach involving customer personally identifiable information (PII). The incident response team has completed containment and eradication. Legal counsel advises that the breach may trigger notification requirements under multiple jurisdictions. Which of the following should the security manager do NEXT to ensure compliance?

A.Delete all compromised data to prevent further exposure.
B.Conduct a thorough impact assessment to determine the scope and nature of the data involved.
C.Publicly announce the breach on the company website to demonstrate transparency.
D.Immediately send a blanket notification to all customers regardless of jurisdiction.
AnswerB

Before notifying regulators or affected individuals, the organization must understand exactly what data was compromised, how many records, and which jurisdictions are affected. This impact assessment informs legal notification obligations and the content of notifications. It is a critical step to ensure accurate and compliant reporting, and it aligns with CISM's emphasis on risk assessment and legal coordination during incident recovery.

Why this answer

After containment and eradication, the next critical step in a data breach involving PII is to assess the scope and impact. This assessment identifies which data elements were exposed, how many individuals are affected, and which jurisdictions' laws apply. It provides the factual basis for legal notification decisions and ensures that notifications are accurate, timely, and compliant with varying regulatory requirements.

Exam trap

The trap here is rushing to notify customers or the public without first determining the scope of the breach, which can lead to non-compliant or inaccurate notifications and unnecessary panic.

102
MCQhard

An organization is required to report a material cybersecurity incident to the SEC within 4 business days (proposed rule). However, the incident is still under investigation. What is the BEST course of action?

A.File a report with the information available and provide updates as the investigation progresses.
B.Request an extension from the SEC because the investigation is ongoing.
C.Delay reporting until the investigation is complete to ensure accuracy.
D.Report the incident only if materiality is confirmed at the end of the investigation.
AnswerA

SEC rules permit filing with incomplete details provided you amend promptly, so filing within the 4-business-day deadline satisfies the reporting constraint while updates cover the ongoing investigation. Waiting for full findings breaches the deadline; silence is not an option.

Why this answer

Regulatory deadlines must be met even if information is incomplete; disclose what is known and update later.

103
MCQmedium

An organization's incident response team has contained a ransomware incident. What is the NEXT step according to the incident management program?

A.Eradicate the malware and restore systems
B.Perform root cause analysis
C.Conduct a lessons learned meeting
D.Notify regulatory authorities
AnswerA

Containment stops spread but leaves malicious artefacts resident. Eradication removes malware, persistence mechanisms, and compromised accounts, after which systems are restored from trusted backups. This follows the incident management lifecycle sequence, so eradication and restoration is the next step after containment.

Why this answer

After containment, the next priority is eradication of the threat to remove all traces of the malware and restore systems securely.

104
MCQmedium

In the context of incident management, which of the following is the PRIMARY purpose of conducting lessons learned meetings within two weeks of incident resolution?

A.To update the incident response plan and playbooks based on findings.
B.To provide a final report to regulators and law enforcement.
C.To assign blame for the incident and take disciplinary action.
D.To calculate the total financial loss from the incident.
AnswerA

Conducting lessons learned within two weeks, while details remain fresh, enables prompt revision of the incident response plan and playbooks. This directly satisfies the stem's primary purpose, embedding findings into documented procedures before organisational memory fades.

Why this answer

The main goal is to improve future incident response by identifying what worked and what didn't.

105
MCQmedium

An organization has experienced a ransomware attack that has encrypted critical servers and is causing major business disruption. According to incident severity levels, which priority should this incident be assigned?

A.P2 — High
B.P4 — Low
C.P1 — Critical
D.P3 — Medium
AnswerC

P1 Critical is reserved for incidents causing major business disruption, such as encrypted critical servers halting operations. It triggers immediate escalation, full crisis team activation and continuous response until resolved, matching the severity criteria stated in the stem.

Why this answer

A ransomware attack that encrypts critical servers and causes major business disruption is a critical incident, warranting a P1 priority. P1 incidents are reserved for those with severe impact on business operations, requiring immediate response and escalation. The encryption of critical servers directly threatens the organization's ability to operate, making P1 the appropriate severity level.

Exam trap

The trap is underestimating the severity of a ransomware attack on critical servers, leading candidates to choose P2 or P3 instead of recognizing the major business disruption as P1.

How to eliminate wrong answers

Option A is wrong because P2 (High) is for significant incidents that impact important functions but do not cause major business disruption or affect critical servers; the described scenario is more severe. Option B is wrong because P4 (Low) is for minor incidents with negligible impact, which is clearly not the case here. Option D is wrong because P3 (Medium) is for moderate incidents that cause limited disruption, whereas this ransomware attack has major business disruption, elevating it to P1.

106
Multi-Selecthard

Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)

Select 2 answers
A.Allowing the firm to make independent decisions on containment
B.Having the firm report directly to the media
C.Maintaining chain of custody for all evidence
D.Defining the scope of work and evidence handling procedures
E.Ensuring the firm uses only proprietary tools
AnswersC, D

Chain of custody preserves evidence integrity so it remains admissible in legal or disciplinary proceedings. When an external firm handles artefacts, unbroken documented transfer records satisfy the evidentiary constraint the scenario demands, preventing challenges to forensic findings.

Why this answer

Option C is correct because maintaining chain of custody is essential when an external forensics firm handles evidence; documented, unbroken custody records ensure the evidence remains admissible in legal or disciplinary proceedings and prevents tampering or spoliation. Option D is correct because a clear scope of work plus agreed evidence-handling procedures define what the firm will investigate, how it will collect and preserve data, and what deliverables and timelines apply, preventing misunderstandings and unauthorized actions. The unmarked options do not belong: A is wrong because containment decisions should remain with the incident response team or management under the organization's authority, not be delegated independently to the forensics firm; B is wrong because media communications must go through the organization's designated spokesperson or PR/legal team, not the external firm; and E is wrong because requiring only proprietary tools is unnecessary and can hinder analysis, whereas validated, forensically sound tools and documented methods are what matter.

107
MCQmedium

During a suspected insider data theft, a security manager discovers that an employee copied sensitive pricing files to a personal cloud drive two weeks ago. Legal counsel has not yet decided whether to pursue legal action. The security manager must decide how to treat the forensic copies of the employee's laptop image and cloud access logs. Which action BEST aligns with evidence handling requirements?

A.Copy the evidence to a shared network folder so legal, HR, and IT can all review it as needed
B.Maintain a documented chain of custody, hash the images, and store them in a restricted evidence repository
C.Allow the employee to continue working normally while quietly monitoring activity to gather more evidence
D.Delete the laptop image after extracting only the relevant pricing files to reduce storage and privacy risk
AnswerB

Forensic evidence must remain admissible and defensible, which requires verifiable integrity and unbroken custody. Hashing the images at acquisition proves they were not altered, while a documented chain of custody records every transfer, and a restricted repository prevents tampering. Because litigation is still undecided, preserving evidence in this rigorous manner keeps all options open. This approach satisfies both internal investigation needs and potential legal proceedings without prejudging the outcome.

Why this answer

When litigation is undecided, the safest course is to preserve evidence so it remains usable in any proceeding. Hashing the forensic images at acquisition, documenting every transfer in a chain of custody, and storing copies in a restricted repository together establish integrity and control. These steps prevent alteration, support authentication, and keep access limited.

Continued monitoring without preservation, selective deletion, or broad sharing all risk destroying or contaminating evidence before legal counsel determines the organization's position.

Exam trap

The trap here is treating the investigation as purely internal and skipping formal evidence controls, when undecided litigation makes chain of custody and hashing essential from the first acquisition.

108
MCQmedium

An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?

A.Data breach playbook
B.Ransomware playbook
C.Credential compromise playbook
D.Insider threat playbook
AnswerC

Phishing that yields unauthorised account access is credential compromise, so the credential compromise playbook prescribes password resets, session revocation, MFA enforcement and account monitoring. A malware or data breach playbook would not address the stolen-credential vector that enabled the intrusion.

Why this answer

Credential compromise incidents, such as account takeover via phishing, are handled by the credential compromise playbook.

109
MCQhard

During a data breach investigation, an organization engages an external forensics firm. To preserve attorney-client privilege, which of the following is the BEST practice?

A.Engage the forensics firm under the direction of legal counsel.
B.Have the forensics firm work independently to maintain objectivity.
C.Ensure the forensics firm signs a non-disclosure agreement only.
D.Have the forensics firm report directly to the CISO.
AnswerA

Engaging the forensics firm under legal counsel's direction extends attorney-client privilege to the firm's work product, satisfying the stem's privilege-preservation constraint. Counsel retains the vendor, directs the investigation, and receives findings, so communications and deliverables fall within privilege rather than becoming discoverable business records.

Why this answer

Engaging the forensics firm under the direction of legal counsel is the best practice because it extends attorney-client privilege to the investigation. When counsel directs the work, communications and findings are protected as work product, preventing disclosure in litigation. This is a foundational principle in incident response legal strategy.

Exam trap

The trap here is that candidates confuse confidentiality (NDA) with legal privilege, or assume operational independence (reporting to CISO) is acceptable, when only attorney-directed engagement preserves privilege under evidentiary rules.

How to eliminate wrong answers

Option B is wrong because having the forensics firm work independently to maintain objectivity would break the privileged relationship; independent work without legal direction creates discoverable evidence. Option C is wrong because a non-disclosure agreement only protects confidentiality, not legal privilege; it does not shield the investigation from being subpoenaed. Option D is wrong because having the forensics firm report directly to the CISO bypasses legal counsel, making the investigation subject to discovery as ordinary business records.

110
Multi-Selectmedium

An organization is reviewing its incident response plan after a prolonged outage caused by a coordinated attack. Management wants to improve the organization's ability to communicate effectively during future incidents. Which TWO of the following should be included in the incident communication plan? (Choose two.)

Select 2 answers
A.A requirement that all technical details of the incident be shared publicly in real time
B.A list of all employees' personal mobile numbers for emergency mass texting
C.A policy that only the CEO may speak to any stakeholder during an incident
D.Predefined communication templates for different stakeholder groups and incident types
E.Designated spokespersons and approval workflows for external communications
AnswersD, E

Predefined templates accelerate communication during high-pressure incidents and ensure consistent, accurate messaging. They reduce the risk of ad hoc statements that could create legal or reputational problems. CISM recommends preparing templates for internal staff, customers, regulators, and media in advance. This directly improves the organization's ability to communicate effectively when time and attention are constrained.

Why this answer

An effective incident communication plan includes prepared templates for different audiences and incidents, plus designated spokespersons with clear approval workflows. Templates speed response and ensure consistency, while spokesperson designation and approval controls prevent unauthorized or harmful statements. Collecting personal contact data, mandating real-time technical disclosure, or centralizing all communication in one executive do not constitute sound communication planning and can introduce privacy, security, or operational problems.

Exam trap

The trap here is equating more communication with better communication, leading to choices that over-share, over-centralize, or collect unnecessary personal data.

111
MCQmedium

An organization is updating its incident response playbook after a ransomware attack. Which of the following should be included as a key step in the ransomware playbook?

A.Reboot all servers to clear the ransomware
B.Immediately pay the ransom demand
C.Isolate affected systems from the network
D.Notify all customers immediately
AnswerC

Isolating affected systems cuts command-and-control and lateral movement paths, preventing the ransomware from spreading to further hosts before eradication and recovery begin. This satisfies the stem's requirement for a key playbook step, and preserves the isolated systems for later forensic examination.

Why this answer

Ransomware playbooks should include isolating infected systems to prevent spread, as containment is a priority.

112
Multi-Selectmedium

Which TWO of the following are required components of an incident response programme according to best practices? (Select two.)

Select 2 answers
A.IR team roster
B.Incident response policy
C.Incident response plan
D.Communication templates
E.Vendor contacts list
AnswersB, C

An incident response policy supplies the mandated authority, scope and governance framework that best practice requires before any procedural or technical capability is built. It defines roles, escalation thresholds and management commitment, satisfying the programme's foundational requirement. Without it, plans and playbooks lack approved direction, so this option is a required component.

Why this answer

Option B (Incident response policy) is correct because best-practice frameworks such as NIST SP 800-61 and ISO/IEC 27035 require a formally approved policy that establishes the authority, scope, objectives, and management commitment for the incident response capability. Option C (Incident response plan) is correct because the plan is the documented, actionable set of procedures—roles, phases (preparation, detection and analysis, containment, eradication, recovery, post-incident activity), and escalation paths—that operationalizes the policy. The remaining items are supporting artifacts rather than required programme components: an IR team roster (A), communication templates (D), and a vendor contacts list (E) are useful appendices or resources referenced by the plan, but they are not themselves mandatory components of an incident response programme.

Exam trap

A common trap in CISM is distinguishing between the policy (the 'what' and 'why') and the plan (the 'how'), leading candidates to select operational items like contact lists or templates instead of the mandatory governance components.

113
MCQhard

An organization is conducting a root cause analysis after an insider threat incident. Which of the following tools is MOST appropriate for identifying the underlying management governance failure?

A.Risk assessment
B.SWOT analysis
C.5 Whys
D.Gap analysis
AnswerC

5 Whys iteratively probes causal layers beyond the immediate actor, exposing management governance failures such as inadequate segregation of duties, absent oversight or weak policy enforcement. Technical tools identify what happened; only causal questioning reaches the underlying governance deficiency that enabled the insider threat.

Why this answer

The 5 Whys technique is a simple but effective method to drill down from technical cause to process failure to management failure.

114
MCQmedium

An organization is subject to GDPR and experiences a data breach involving personal data. What is the maximum timeframe to notify the supervisory authority?

A.24 hours
B.48 hours
C.7 days
D.72 hours
AnswerD

GDPR Article 33 mandates notifying the supervisory authority within 72 hours of becoming aware of a personal data breach, unless it poses no risk to rights and freedoms. This precise deadline directly satisfies the question's maximum timeframe requirement.

Why this answer

GDPR requires notification within 72 hours of becoming aware of the breach.

115
MCQhard

After a data breach involving personal data of EU residents, the incident manager must ensure compliance with GDPR notification requirements. Within how many hours must the organization notify the relevant supervisory authority of the breach?

A.96 hours
B.24 hours
C.48 hours
D.72 hours
AnswerD

GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk to data subjects. This fixed regulatory deadline is the constraint the incident manager must satisfy.

Why this answer

GDPR Article 33 requires that, in the event of a personal data breach, the controller must notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The 72-hour clock is a hard regulatory deadline, and failure to meet it can trigger significant fines under Article 83. This is why 72 hours is the correct answer for breach notification to the supervisory authority.

Exam trap

CISM often tests the specific 72-hour GDPR breach notification deadline, and candidates frequently confuse it with the 24-hour or 48-hour windows used in other regulations or internal SLAs.

How to eliminate wrong answers

Option A (96 hours) is wrong because it exceeds the GDPR-mandated 72-hour window and is not a recognized regulatory deadline. Option B (24 hours) is wrong because it reflects the shorter timeline sometimes associated with NIS2 or certain sector-specific rules, not GDPR Article 33. Option C (48 hours) is wrong because it is a common distractor that sounds plausible but has no basis in GDPR breach notification requirements.

116
MCQmedium

An organization is updating its incident response plan after a lessons learned meeting. Which of the following is the primary purpose of updating the plan based on lessons learned?

A.To assign blame for failures
B.To share threat intelligence with ISACs
C.To incorporate improvements to prevent recurrence and enhance response
D.To document the incident for regulatory compliance
AnswerC

Lessons learned exists to close the gap between planned and actual response. Feeding findings back into the plan incorporates corrective improvements, reducing the likelihood of recurrence and strengthening future response capability, which is the stated primary purpose of the update.

Why this answer

The primary purpose of updating an incident response plan after a lessons learned review is to feed identified gaps, control failures, and response inefficiencies back into the plan so future incidents are prevented or handled more effectively. This closes the continuous improvement loop central to frameworks like NIST SP 800-61 and ISO 27035. The update is a corrective and preventive action, not a documentation or blame exercise.

Exam trap

CISM often tests the distinction between the primary purpose of an activity and its secondary benefits — candidates pick 'regulatory compliance' or 'threat sharing' because those sound governance-oriented, but the primary purpose is always continuous improvement of response capability.

How to eliminate wrong answers

Option A is wrong because assigning blame is counterproductive and contrary to the blameless post-mortem philosophy that underpins effective IR programs — the goal is systemic improvement, not individual accountability. Option B is wrong because sharing threat intelligence with ISACs is a separate external-sharing activity; it may result from lessons learned but is not the primary purpose of updating the IR plan itself. Option D is wrong because regulatory documentation is a byproduct of incident handling, not the driver for revising the plan — compliance documentation does not inherently improve response capability.

117
MCQhard

A financial services firm has activated its incident response team for a suspected insider data theft. The legal department advises that the matter may become a criminal case. The security manager must decide how to handle the forensic images and analyst notes. Which action BEST supports both the investigation and potential legal proceedings?

A.Delete analyst working notes after the final report is issued to reduce discoverable material
B.Store all evidence on the same file server used for routine IT backups to ensure redundancy
C.Allow the suspect's manager to review the forensic images to confirm whether the data was sensitive
D.Maintain a documented chain of custody with hash values and restricted access to the evidence repository
AnswerD

A documented chain of custody, cryptographic hashes, and access controls preserve evidence integrity and demonstrate that it has not been altered. This is essential for admissibility in legal proceedings and for defending investigative conclusions. CISM emphasizes that evidence handling procedures must be defined before incidents occur and followed rigorously, especially when criminal prosecution or regulatory action is possible.

Why this answer

When an incident may become a criminal or civil legal matter, evidence must be handled so that it remains admissible and defensible. Chain of custody documentation, cryptographic hashing, and strict access controls are the core requirements. These practices demonstrate that evidence has not been altered and that only authorized personnel handled it.

Other options either contaminate evidence, expose it to unauthorized parties, or destroy potentially discoverable material.

Exam trap

The trap here is treating evidence like ordinary IT data that needs redundancy or cleanup, rather than recognizing that legal admissibility requires isolation, hashing, and documented custody.

118
MCQeasy

An incident response team is conducting an exercise to test its playbook for a ransomware incident. Which of the following is the PRIMARY benefit of such an exercise?

A.Validating the incident response plan and identifying areas for improvement
B.Documenting the exercise for future reference
C.Complying with regulatory requirements
D.Testing the technical skills of the team
AnswerA

Exercising the playbook validates that documented procedures actually work under realistic ransomware conditions, exposing gaps such as unclear escalation paths, missing containment steps or untested recovery dependencies. This directly satisfies the stem's test objective: confirming the plan's effectiveness and surfacing improvement areas before a real incident, rather than merely reviewing documentation.

Why this answer

The primary purpose of a tabletop or simulation exercise is to validate that the incident response plan works in practice and to surface gaps, ambiguities, and missing roles before a real ransomware event occurs. Exercises reveal whether contact lists are current, escalation paths are clear, and playbook steps are executable — findings that directly feed plan improvement.

Exam trap

CISM often tests the difference between the primary benefit of an activity and its secondary outputs — candidates pick 'documentation' or 'compliance' because those are tangible, but the exam wants the core purpose: validating and improving the plan.

How to eliminate wrong answers

Option B is wrong because documentation is a byproduct of the exercise, not its primary benefit — the goal is validation and improvement, not record-keeping. Option C is wrong because regulatory compliance may be a driver for conducting exercises, but compliance is a secondary outcome; the exercise's value is in testing and refining the plan. Option D is wrong because while technical skills are exercised, the primary benefit is validating the plan and process, not assessing individual team members' technical proficiency.

119
MCQmedium

A security manager is drafting the incident classification section of the incident response plan. Executives want a documented, repeatable way to rank incidents so that notification and escalation paths are triggered consistently. Which of the following should be the PRIMARY basis for assigning an incident severity level?

A.The number of security alerts generated by the detection tooling during the event.
B.The assessed business impact and the criticality of the affected information assets.
C.The elapsed time between the first log entry and the moment the analyst opens the ticket.
D.The technical sophistication of the attacker's tools and malware used in the intrusion.
AnswerB

Severity exists to align response effort and escalation with the harm an incident can cause, so it must be derived from business impact and asset criticality. This lets the same event type be rated differently depending on which systems and data are touched. It also produces consistent, defensible escalation to management, which is exactly what the incident response plan and governance require.

Why this answer

Severity classification must translate technical events into business consequences so that escalation, notification, and resource allocation are consistent and defensible. Basing severity on business impact and asset criticality ensures identical event types can be triaged differently according to what is at stake, and it gives management a repeatable trigger for its involvement.

Exam trap

The trap here is assuming severity should track technical drama such as attacker sophistication or alert volume rather than the actual business impact of the affected assets.

120
MCQeasy

Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?

A.Chief Information Security Officer
B.Incident response manager
C.External legal counsel
D.Board of directors
AnswerC

External legal counsel sits outside the organisation yet is engaged during incidents for breach notification, regulatory and privilege advice. Listing them as a vendor contact satisfies the stem's requirement for an external stakeholder, since internal roles such as the CISO or IT staff are not external parties.

Why this answer

External legal counsel is an external stakeholder because they are not employees of the organization but are engaged to provide specialized legal advice during incidents. In an incident response plan, vendor contacts must include external parties such as legal counsel, forensic firms, and PR agencies who can be called upon when needed. The CISO, incident response manager, and board of directors are all internal roles and would not be listed as vendor contacts.

Exam trap

CISM often tests the distinction between internal roles and external stakeholders, and candidates may incorrectly assume that high-level executives like the CISO or board are external because they have oversight responsibilities.

How to eliminate wrong answers

Option A is wrong because the Chief Information Security Officer is an internal executive responsible for the organization's security program, not an external vendor. Option B is wrong because the incident response manager is an internal role that coordinates the IR team, not an external contact. Option D is wrong because the board of directors is an internal governance body, not an external stakeholder or vendor.

121
MCQhard

During a suspected insider data theft investigation, the incident response team discovers that the suspect's laptop is still powered on and logged in. Legal counsel advises that evidence must be preserved for potential litigation. Which of the following actions should the team take FIRST?

A.Capture volatile data such as memory and network connections, then isolate the system from the network.
B.Immediately shut down the laptop to prevent the suspect from deleting evidence remotely.
C.Disconnect the laptop from the network immediately and begin imaging the hard drive.
D.Ask the suspect to remain logged in while the team interviews them about the alleged activity.
AnswerA

Capturing volatile data first preserves memory-resident evidence, active network connections, and encryption keys that would be lost on shutdown. Isolating the system from the network afterward prevents remote tampering or further data exfiltration while maintaining the system state. This sequence aligns with forensic best practices and supports legal preservation requirements, making it the most defensible first action in this scenario.

Why this answer

Forensic best practice is to capture volatile data before isolating or powering down a live system. Memory, active network connections, and encryption keys can vanish on shutdown or network disconnection, and they may be crucial to proving insider theft. After volatile data is secured, isolating the system prevents remote tampering and further exfiltration while preserving the remaining evidence for legal use.

Exam trap

The trap here is prioritizing immediate containment over evidence preservation, when volatile data must be captured first to avoid permanently losing critical forensic artifacts.

122
MCQeasy

An organization has just completed containment of a malware outbreak. The incident manager is preparing to transition the incident to the eradication and recovery phase. Which activity should occur FIRST during this transition?

A.Identify and remove the root cause and all remnants of the malware from affected systems
B.Notify external regulators of the incident in accordance with legal requirements
C.Restore all affected systems from the most recent backups and return them to production
D.Conduct a lessons-learned meeting with all incident responders
AnswerA

Eradication focuses on eliminating the root cause and any residual malicious components so the threat cannot recur. Transitioning from containment to eradication means the organization has stabilized the situation and can now remove the threat. Recovery, which follows, restores systems to normal operation. Performing eradication first prevents reinfection during recovery and is the defining activity of this phase.

Why this answer

The incident response lifecycle moves from preparation to detection and analysis, containment, eradication, recovery, and post-incident activity. Once containment is achieved, the next phase is eradication, which removes the root cause and residual threat. Recovery, regulatory notification, and lessons learned come later.

Performing eradication before recovery prevents reinfection and ensures that restored systems are not compromised again by the same vector.

Exam trap

The trap here is confusing recovery with eradication, assuming that restoring from backup resolves the incident before the root cause has been removed.

123
MCQhard

During a major data breach, the incident response manager needs to determine whether the organization must notify regulators and affected individuals. Which factor is MOST important in making this determination?

A.The estimated cost of the incident response effort.
B.The number of systems affected by the malware.
C.The length of time the attacker had access to the environment.
D.The type of data compromised and applicable legal and regulatory requirements.
AnswerD

Notification obligations are driven by the classification of the data involved and the laws or regulations that apply to the organization, such as privacy statutes, industry rules, or contractual requirements. Determining whether personal, financial, or health information was exposed, and in which jurisdictions, allows legal counsel and compliance to assess mandatory reporting timelines and thresholds accurately.

Why this answer

Notification decisions are legal and compliance determinations based on what data was exposed and which laws, regulations, or contracts apply. The incident response manager should engage legal counsel and privacy officers early to map the compromised data types to specific reporting obligations and deadlines. Operational metrics such as system count, dwell time, and response cost inform the investigation but do not by themselves establish a duty to notify.

Exam trap

The trap here is equating the scale of the technical compromise, such as the number of infected systems, with the legal trigger for notification, when the actual trigger is the type of regulated data exposed.

124
MCQmedium

When an incident cannot be resolved within the maximum tolerable downtime (MTD), what is the appropriate action regarding business continuity and disaster recovery (BC/DR)?

A.Ignore the MTD and focus solely on incident eradication
B.Continue incident response until full recovery
C.Declare a disaster immediately without further analysis
D.Escalate to the BC/DR team for possible activation of continuity plans
AnswerD

Once recovery cannot meet the maximum tolerable downtime, the incident exceeds IT response capability and becomes a business continuity matter. Escalating to the BC/DR team enables assessment and possible activation of continuity plans to sustain critical business functions.

Why this answer

The Maximum Tolerable Downtime (MTD) is the longest time a business process can be unavailable before causing unacceptable impact. When an incident cannot be resolved within the MTD, the appropriate action is to escalate to the BC/DR team so they can decide whether to activate continuity plans (e.g., failover to alternate sites, manual workarounds). Continuing incident response past the MTD without invoking BC/DR risks exceeding the organization's tolerance for downtime.

Exam trap

CISM often tests the misconception that incident response should always continue until full recovery, when in fact MTD breach requires escalation to BC/DR for continuity activation decisions.

How to eliminate wrong answers

Option A is wrong because ignoring the MTD and focusing only on eradication can lead to unacceptable business impact — MTD is a governance trigger, not a suggestion. Option B is wrong because continuing incident response until full recovery may exceed the MTD and delay continuity activation, which is precisely what MTD is designed to prevent. Option C is wrong because declaring a disaster immediately without analysis is premature; escalation to the BC/DR team allows a structured decision based on MTD breach and impact.

125
Multi-Selectmedium

An information security manager is building the organization's incident response capability and wants to ensure the team can effectively detect, analyze, and respond to incidents. Which TWO of the following are essential elements that should be established before an incident occurs? (Choose two.)

Select 2 answers
A.Documented roles, responsibilities, and contact details for the response team and key internal stakeholders
B.A complete inventory of every software vulnerability present across the enterprise
C.A defined incident classification and severity scheme agreed with business stakeholders
D.A guarantee that no incident will escalate beyond the technical response team
E.A published list of the organization's security tool vendors for marketing purposes
AnswersA, C

Clear roles and current contact information let the team mobilize quickly and avoid confusion about who decides, who communicates, and who executes. This is foundational to any response capability because incidents rarely occur during business hours with everyone available. Without defined responsibilities, response stalls at the moment speed matters most, increasing impact and cost.

Why this answer

Effective incident response depends on shared severity definitions and clearly assigned roles with current contacts, because these determine how quickly and consistently the organization triages, escalates, and coordinates. A vulnerability inventory supports prevention rather than response, while assuming incidents stay technical and publishing vendor lists for marketing do not strengthen the capability and can even increase exposure.

Exam trap

The trap here is selecting preventive or promotional activities, such as vulnerability inventories or vendor marketing lists, when the question asks specifically about pre-established incident response capability elements.

126
MCQmedium

An organization's incident response team has contained a malware outbreak, but the attacker's initial access vector remains unknown. Which activity should be performed to reduce the likelihood of recurrence?

A.Notify all employees about the incident and remind them of security policies.
B.Increase the frequency of antivirus signature updates on all endpoints.
C.Perform a root cause analysis to identify and remediate the initial access vector.
D.Close the incident and restore affected systems from backups.
AnswerC

Root cause analysis examines logs, forensic artifacts, and timeline data to determine how the attacker gained entry, such as a phishing email, exposed service, or stolen credential. Identifying and remediating that vector prevents recurrence and informs improvements to controls, monitoring, and the incident response plan. It also supports lessons learned and any regulatory or insurance reporting requirements.

Why this answer

When the initial access vector is unknown, the highest priority is a structured root cause analysis to determine how the attacker entered and to eliminate that pathway. This prevents recurrence and feeds lessons learned into control improvements, monitoring enhancements, and plan updates. Recovery, signature updates, and awareness communications are useful supporting activities, but none of them replaces identifying and closing the actual entry point.

Exam trap

The trap here is treating recovery and closure as the end of the incident, when an unknown access vector means the root cause has not been addressed and the environment remains exposed.

127
MCQhard

During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?

A.Immediately power off the server to stop all malicious activity and prevent further data loss
B.Rebuild the server from a known-good image immediately to restore service and remove any attacker foothold
C.Isolate the server from the network at the switch or host firewall level while keeping it powered on for volatile data collection
D.Leave the server online and continue monitoring the command-and-control traffic to gather more intelligence on the attacker
AnswerC

Network isolation stops command-and-control communication and lateral movement while keeping the system running so memory, active connections, and process state can be captured. This preserves volatile evidence and supports scoping the intrusion, satisfying both containment and investigation needs. It is the standard balanced approach when a system must be contained without destroying forensic value.

Why this answer

The best balance is to contain the system without destroying volatile evidence. Network isolation stops malicious communication and lateral movement while leaving memory, running processes, and active connections intact for collection. Powering off, prolonged passive monitoring, or immediate rebuild each sacrifice either containment or investigative capability, so they fail to meet both requirements simultaneously.

Exam trap

The trap here is equating containment with shutting the system down, when isolation actually contains the threat while preserving the volatile evidence needed for investigation.

128
MCQhard

An organization operates in multiple jurisdictions and suffers a breach involving personal data of customers in several countries. The incident response manager must coordinate communication with regulators, customers, and internal stakeholders while the technical investigation continues. Which of the following is the MOST important consideration when developing the incident communication strategy?

A.Ensure all external communications are approved through legal counsel and aligned with applicable regulatory notification requirements and deadlines.
B.Release detailed technical findings immediately to all customers so they can assess their own risk without delay.
C.Delay all notifications until the forensic investigation is fully complete to ensure accuracy in every statement.
D.Allow each regional business unit to communicate independently using its own messaging and timing without central coordination.
AnswerA

Breach notification obligations vary by jurisdiction and often carry strict deadlines, content requirements, and prescribed recipients. Legal counsel must review external communications to avoid conflicting statements, waiving privileges, or missing mandatory timelines. Aligning messages with regulatory requirements protects the organization from penalties and ensures affected parties receive accurate, timely information while the investigation continues.

Why this answer

Multi-jurisdiction breaches trigger overlapping notification laws with different deadlines and content rules, so external communications must be reviewed by legal counsel and mapped to each applicable requirement. This ensures deadlines are met, statements are consistent, and privileges or ongoing investigations are not compromised. Timely, accurate, and compliant communication protects the organization legally and preserves stakeholder trust while the technical investigation proceeds in parallel.

Exam trap

The trap here is choosing between speed and completeness of disclosure, when the governing consideration is legal review and alignment with jurisdiction-specific notification requirements and deadlines.

129
MCQhard

An organization has experienced a ransomware attack that has encrypted critical servers. The incident response team is unable to contain the incident within the maximum tolerable downtime (MTD). Who has the authority to declare a disaster and activate the business continuity plan?

A.The incident response manager
B.The chief executive officer (CEO) or designated crisis management team
C.The business continuity manager
D.The chief information security officer (CISO)
AnswerB

Declaring a disaster exceeds operational incident authority, requiring executive mandate to commit organisation-wide resources and invoke continuity arrangements. The CEO or designated crisis management team holds that strategic authority, satisfying the stem's MTD-exceeded escalation trigger.

Why this answer

The CEO or designated crisis management team holds the authority to declare a disaster and activate the BCP because this decision has enterprise-wide impact, requiring executive-level accountability and resource allocation. The CEO is ultimately responsible for business survival, and the crisis management team is typically pre-authorized to make this call when MTD is exceeded. This aligns with CISM's governance principle that business continuity is a business decision, not an IT or security decision.

Exam trap

CISM often tests the distinction between tactical incident response roles and strategic business continuity authority, causing candidates to incorrectly assume the CISO or BCP manager can declare a disaster.

How to eliminate wrong answers

Option A is wrong because the incident response manager focuses on tactical containment and recovery of the incident, not on declaring a disaster or activating the BCP—that authority resides at the executive level. Option C is wrong because the business continuity manager coordinates BCP development and maintenance but typically does not have the authority to declare a disaster; that decision requires executive approval. Option D is wrong because the CISO is responsible for information security strategy and may advise on the incident, but declaring a disaster and activating the BCP is a business continuity governance decision, not a security function.

130
MCQeasy

An organization has experienced a security incident involving unauthorized access to a system containing customer data. The incident response team has contained the incident. According to CISM best practices, which of the following should be performed NEXT?

A.Notify affected customers about the data breach.
B.Eradicate the root cause of the incident.
C.Recover the affected systems to normal operations.
D.Conduct a lessons learned session.
AnswerB

This is correct because after containment, the next phase in the incident response lifecycle is eradication. Eradication involves removing the cause of the incident, such as malware, backdoors, or vulnerabilities, to prevent recurrence. CISM follows the standard incident response phases: preparation, identification, containment, eradication, recovery, and lessons learned. Eradication must be completed before recovery to ensure the environment is clean.

Why this answer

After containment, the incident response team should proceed to eradication to remove the root cause of the incident. This ensures that the threat is eliminated before recovery. Recovery, lessons learned, and customer notification are subsequent steps.

CISM emphasizes a structured incident response process, and eradication is the logical next phase after containment to prevent the incident from recurring.

Exam trap

The trap here is thinking that recovery or notification comes immediately after containment, when actually eradication must occur first to prevent recurrence.

131
MCQeasy

Which incident category typically involves an employee intentionally or accidentally causing harm to the organization's information systems?

A.Data breach
B.DDoS
C.Ransomware
D.Insider threat
AnswerD

Insider threats uniquely cover harm caused by employees, whether malicious or accidental, matching the stem's requirement for internal actors. Unlike external categories such as hacktivists or nation-states, this classification hinges on the actor's authorised access and trusted position within the organisation, satisfying the intent and origin constraints.

Why this answer

An insider threat is the correct category because it specifically involves harm caused by individuals within the organization, whether through malicious intent (e.g., data exfiltration, sabotage) or accidental actions (e.g., misconfiguration, phishing click). This aligns with the CISM definition of insider threats as incidents originating from employees, contractors, or trusted partners who have authorized access to information systems.

Exam trap

ISACA CISM often tests the distinction between the incident category (who or what caused it) and the incident type or outcome, leading candidates to confuse 'insider threat' with 'data breach' because a data breach can be caused by an insider, but the question asks for the category that involves the employee's action.

How to eliminate wrong answers

Option A is wrong because a data breach is the outcome or result of an incident (e.g., unauthorized access or disclosure of data), not the category of the actor or cause; it does not specify whether the source is internal or external. Option B is wrong because a DDoS (Distributed Denial of Service) attack is an external, volumetric network attack that overwhelms system resources, typically launched from botnets, not from an employee's intentional or accidental actions. Option C is wrong because ransomware is a type of malware that encrypts files for extortion, usually delivered via external phishing or exploit kits, and does not inherently involve an employee's direct action causing harm to systems.

132
MCQeasy

Which of the following is the PRIMARY purpose of conducting a lessons learned meeting after an incident?

A.To assign blame for the incident.
B.To determine the financial impact of the incident.
C.To document the incident for regulatory reporting.
D.To update the incident response plan and playbooks based on findings.
AnswerD

The meeting's output is corrective: identified gaps, control failures and response weaknesses are translated into revised procedures, playbooks and controls. Without feeding findings back into the plan, the same deficiencies recur, so plan and playbook updates are the primary purpose rather than blame allocation or reporting.

Why this answer

Lessons learned meetings are designed to identify strengths and weaknesses in the incident response process and to implement improvements.

133
Multi-Selecthard

Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?

Select 3 answers
A.Placing a legal hold on relevant data
B.Maintaining a documented chain of custody
C.Performing analysis directly on original systems
D.Using automated tools without validation
E.Creating bit-for-bit forensic copies of affected media
AnswersA, B, E

A legal hold preserves relevant data and prevents routine deletion or alteration once litigation is reasonably anticipated. Issuing it early satisfies the admissibility requirement by ensuring potentially relevant evidence remains intact and available for forensic collection and court presentation.

Why this answer

Option A is correct because a legal hold preserves potentially relevant data and prevents routine deletion or alteration, which is essential for demonstrating that evidence was not spoliated before collection. Option B is correct because a documented chain of custody records every transfer, access, and storage event for the evidence, allowing the court to verify its integrity and authenticity. Option E is correct because creating bit-for-bit forensic copies (forensic images) preserves the original media and allows analysis on a verified duplicate, typically validated with hash values such as MD5 or SHA-256.

Option C is not correct because performing analysis directly on original systems can alter metadata, timestamps, and other artifacts, undermining admissibility. Option D is not correct because using automated tools without validation fails to establish that the tools produce reliable, repeatable results, which is necessary for forensic soundness.

Exam trap

A common misconception is that direct analysis on original systems is acceptable, but in forensic procedures, any direct manipulation of original media is prohibited to avoid altering the evidence and compromising its admissibility.

134
Multi-Selectmedium

After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)

Select 3 answers
A.The management or governance failure that allowed the process failure.
B.The cost of the breach to the organization.
C.The specific employee who clicked the phishing email.
D.The technical vulnerability that allowed the breach.
E.The process failure that allowed the vulnerability to exist.
AnswersA, D, E

Root cause analysis must extend beyond the immediate technical trigger to the governance layer. Examining the management or governance failure that permitted the process failure to persist identifies systemic accountability gaps, enabling corrective controls that prevent similar PII breaches recurring.

Why this answer

According to CISM best practices, root cause analysis after a data breach should focus on systemic and organizational factors rather than individuals or financial impacts. Option A is correct because governance failures—such as inadequate security policies, missing oversight, or lack of executive accountability—are root causes that enable process and control breakdowns. Option D is correct because identifying the specific technical vulnerability (e.g., an unpatched CVE, misconfigured firewall rule, or weak authentication mechanism) explains how the breach was technically possible.

Option E is correct because the process failure (e.g., absent patch management, ineffective change control, or missing vulnerability scanning) is the underlying reason the vulnerability was allowed to persist. Option B is not a root cause factor; cost is a business impact metric used for post-incident evaluation, not causal analysis. Option C is incorrect because blaming a specific employee who clicked a phishing email addresses a symptom, not the systemic root cause, and CISM emphasizes examining control failures rather than individual blame.

135
Multi-Selecthard

An organization is preparing for a potential supply chain incident. According to CISM best practices, which THREE elements should be included in the supply chain incident playbook? (Select THREE.)

Select 3 answers
A.A step-by-step guide for paying ransoms to cybercriminals.
B.Procedures for isolating affected systems and networks.
C.A list of approved vendors for DDoS mitigation services.
D.Communication templates for notifying affected partners and customers.
E.Instructions for contacting the organization's legal counsel.
AnswersB, D, E

Isolation procedures contain the supply chain compromise by severing affected systems and network segments, preventing lateral spread to internal assets and other partners. This satisfies the playbook requirement for a containment element that limits operational and data exposure during an active incident.

Why this answer

Option B is correct because a supply chain incident playbook must include containment procedures that isolate compromised systems and network segments (e.g., disabling switch ports, applying ACLs, or quarantining VLANs) to prevent lateral movement and further propagation from a compromised vendor. Option D is correct because timely, pre-approved communication templates ensure consistent notification of affected partners and customers, satisfying contractual, regulatory, and reputational obligations during a supply chain breach. Option E is correct because contacting legal counsel is essential for assessing liability, regulatory reporting duties, and breach-notification requirements, and this escalation path must be predefined in the playbook.

Option A is not appropriate because CISM best practices never prescribe ransom payment procedures; paying ransoms is discouraged and would not be a standard playbook element. Option C does not belong because a list of approved DDoS mitigation vendors is a procurement/vendor-management artifact, not a core incident response playbook element for a supply chain incident.

136
MCQhard

An organization experiences a data breach involving customer personally identifiable information (PII). The incident response team has contained the breach. Which of the following should be the PRIMARY consideration when deciding whether to notify affected customers?

A.The cost of providing credit monitoring services.
B.The potential impact on the organization's stock price.
C.Legal and regulatory requirements for breach notification.
D.The organization's public relations strategy.
AnswerC

Legal and regulatory requirements, such as GDPR, HIPAA, or state breach notification laws, mandate when and how affected individuals must be notified. These requirements are the primary consideration because failure to comply can result in fines, legal action, and reputational damage. The organization must assess the breach against these laws to determine its obligations.

Why this answer

The primary consideration for notifying affected customers after a data breach is compliance with legal and regulatory requirements. These laws dictate the circumstances, timing, and method of notification. Failure to comply can result in significant penalties and legal liability.

While cost, PR, and stock price are important, they are secondary to legal obligations and the ethical duty to protect customers.

Exam trap

The trap here is focusing on business or PR considerations instead of the mandatory legal and regulatory requirements that govern breach notification.

137
MCQmedium

An organization's incident response team has identified that a data breach involves customer personal information. Which of the following should be done FIRST to preserve evidence for potential litigation?

A.Issue a legal hold to preserve relevant data
B.Notify affected customers
C.Begin system restoration from backups
D.Conduct a root cause analysis
AnswerA

A legal hold immediately suspends routine deletion and preserves all relevant data, satisfying the stem's requirement to preserve evidence first. Issuing it before forensic imaging or notification prevents spoliation, ensuring evidence remains admissible for potential litigation.

Why this answer

Legal hold prevents spoliation of evidence; it must be issued before any remediation that could alter data.

138
Multi-Selecthard

Which TWO of the following are appropriate actions for preserving evidence during a cybersecurity incident?

Select 2 answers
A.Reboot systems to capture volatile memory
B.Create forensic bit-for-bit images of affected systems
C.Issue a legal hold to prevent deletion of relevant data
D.Disconnect affected systems from the network immediately
E.Delete temporary files to free up space
AnswersB, C

A bit-for-bit image captures the complete disk contents, including slack space and deleted data, while leaving the original evidence unaltered for examination. This satisfies the stem's requirement for preserving evidence, maintaining chain of custody and enabling repeatable analysis without contaminating the source.

Why this answer

Option B is correct because creating a forensic bit-for-bit image preserves an exact, verifiable copy of the affected system's storage, including slack space and deleted-file remnants, so analysis can be performed on the copy without altering the original evidence. Option C is correct because a legal hold formally suspends normal data-retention and deletion practices, ensuring that logs, emails, and other potentially relevant records are not destroyed and remain admissible. Option A is wrong because rebooting destroys volatile memory (RAM, cache, running processes) rather than capturing it; live memory acquisition must be done before any shutdown.

Option D is wrong as a blanket evidence-preservation step because pulling the plug can destroy volatile evidence and is a containment action, not a forensic preservation action. Option E is wrong because deleting temporary files spoliates potential evidence and violates the duty to preserve relevant data.

139
Multi-Selecthard

Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)

Select 3 answers
A.Determine what worked well and what did not
B.Assign blame for the incident
C.Share indicators of compromise with an ISAC
D.Develop recommendations for improvement
E.Identify what happened during the incident
AnswersA, D, E

Reviewing what worked and what failed directly satisfies the stem's requirement to identify improvement areas, feeding corrective actions back into the incident response plan. This retrospective analysis exposes control gaps and successful practices, enabling Microsoft Entra ID and other security measures to be tuned against future threats.

Why this answer

Option A is correct because a lessons learned (post-incident) meeting evaluates the incident response to determine what worked well and what did not, so successful practices can be reinforced and gaps addressed. Option D is correct because the meeting's output includes recommendations for improvement, such as updating procedures, controls, or training to prevent recurrence or improve future response. Option E is correct because identifying what happened during the incident — reconstructing the timeline, root cause, and scope — is a core objective that grounds the analysis and subsequent recommendations.

Option B is not an objective; lessons learned meetings are blameless and focus on process improvement rather than assigning fault. Option C is not an objective of the meeting itself; sharing indicators of compromise with an ISAC is a separate threat-intelligence activity that may occur, but it is not a stated goal of the lessons learned session.

140
MCQhard

A company discovers a credential compromise affecting multiple user accounts. According to best practices, what is the first step the incident response team should take?

A.Conduct a root cause analysis
B.Disable compromised accounts and reset passwords
C.Contact law enforcement
D.Notify affected users immediately
AnswerB

Disabling the compromised accounts and resetting passwords immediately terminates the attacker's access and blocks further misuse of those credentials. This containment step precedes deeper investigation, satisfying best practise of stopping active unauthorised access before scoping the full extent of the breach.

Why this answer

When a credential compromise is discovered, the immediate priority is containment to prevent further unauthorized access. Disabling compromised accounts and resetting passwords (Option B) stops the attacker from using the stolen credentials, aligning with the NIST SP 800-61 incident response lifecycle's containment phase. This action directly mitigates the active threat before any forensic analysis or notification occurs.

Exam trap

A common misconception in incident management is that notifying affected users should be the first step. However, according to ISACA's CISM best practices, containment (disabling accounts) must precede notification to prevent further damage and avoid alerting the adversary.

How to eliminate wrong answers

Option A is wrong because root cause analysis is a post-containment step; performing it first would leave compromised accounts active, allowing the attacker to continue lateral movement or data exfiltration. Option C is wrong because contacting law enforcement is a secondary step that typically occurs after containment and evidence preservation, and it does not immediately stop the active compromise. Option D is wrong because notifying affected users immediately could cause panic, tip off the attacker, or lead to data loss if users attempt to investigate on their own; notification should follow a coordinated communication plan after containment.

141
MCQmedium

An organization has experienced a ransomware attack that encrypted critical servers. The incident has been classified as P1. Which of the following is the FIRST action the incident response team should take according to the IR plan?

A.Perform root cause analysis to determine how the ransomware entered.
B.Begin forensic imaging of all affected servers for evidence preservation.
C.Notify the CEO and activate the crisis management team.
D.Contain the incident by isolating affected systems from the network.
AnswerD

Isolating encrypted servers halts lateral spread and further encryption, preserving remaining evidence and business functions before eradication or recovery begins. Containment is the prescribed first phase for a P1 ransomware event, since every minute of continued network access increases damage.

Why this answer

According to standard incident response (IR) frameworks such as NIST SP 800-61 and CISM best practices, the first priority after detecting a P1 incident like ransomware is containment. Isolating affected systems from the network prevents the malware from spreading to other critical servers and limits the blast radius. Only after containment should the team proceed with eradication, recovery, and forensic analysis.

Exam trap

CISM often tests the misconception that root cause analysis or evidence preservation should come before containment; the trap is prioritizing investigation over stopping the active threat, which can lead to wider compromise.

How to eliminate wrong answers

Option A is wrong because root cause analysis is part of the post-incident review and should not be performed before containment; doing so allows the ransomware to continue spreading. Option B is wrong because forensic imaging, while important for evidence, is not the first action; containment takes precedence to stop the attack. Option C is wrong because notifying the CEO and activating the crisis management team is important but secondary to immediate containment; the IR team must first stop the spread, then escalate.

142
MCQeasy

Which of the following is the PRIMARY reason for having a pre-established forensic retainer agreement before an incident occurs?

A.To ensure the forensic firm is familiar with the organization's environment.
B.To reduce the time needed to bring forensic experts on board during an incident.
C.To lock in a favorable pricing structure.
D.To ensure the forensic firm has the necessary certifications.
AnswerB

A retainer pre-negotiates rates, scope, contacts and mobilisation terms, so specialists can be engaged immediately when an incident occurs. This directly removes procurement and contracting delays, preserving volatile evidence and meeting breach notification timelines that would otherwise be missed.

Why this answer

The primary reason for a pre-established forensic retainer agreement is to reduce the time needed to bring forensic experts on board during an incident. In incident management, every minute of delay can allow an attacker to exfiltrate data or destroy evidence; a retainer bypasses the procurement and contracting process, enabling immediate deployment of the forensic team to preserve volatile memory and capture network artifacts.

Exam trap

The CISM exam often tests the distinction between the primary operational benefit (speed of response) and secondary benefits like cost savings or vendor familiarity. The trap here is that candidates select a plausible but secondary reason—such as ensuring the forensic firm knows the environment—instead of recognizing that the retainer's core value is eliminating procurement delays during a crisis.

How to eliminate wrong answers

Option A is wrong because while familiarity with the environment can be beneficial, it is not the primary reason for a retainer; the retainer's main purpose is speed of engagement, not pre-incident knowledge transfer. Option C is wrong because locking in a favorable pricing structure is a secondary financial benefit, not the primary driver for incident response readiness. Option D is wrong because ensuring the forensic firm has necessary certifications is a due diligence step that should be verified during vendor selection, but it is not the core reason for having a retainer agreement in place before an incident.

143
MCQmedium

An organization's incident response plan defines containment, eradication, and recovery phases. During a major incident involving a compromised application server, the incident response manager must decide whether to take the server offline immediately or keep it running to observe attacker behavior. Which of the following is the MOST important factor in making this decision?

A.The attacker's known tactics, techniques, and procedures (TTPs) from threat intelligence.
B.The incident response team's previous experience with similar incidents.
C.The potential business impact of taking the server offline versus the risk of allowing the attacker to persist.
D.The availability of forensic tools to capture volatile memory before shutting down the server.
AnswerC

This is correct because the containment decision must balance business impact against security risk. The incident response manager should assess how critical the server is to business operations and the potential damage if the attacker remains. This aligns with CISM's focus on aligning incident response with business objectives. The other options are less directly relevant to the immediate containment trade-off.

Why this answer

The containment decision during an incident must balance the risk of continued attacker presence against the business impact of taking systems offline. CISM emphasizes aligning incident response with business objectives, so the incident response manager should prioritize business impact and risk. Forensic preservation, threat intelligence, and past experience are supporting considerations but not the primary factor.

Exam trap

The trap here is assuming that forensic preservation always takes precedence over business impact, when in fact containment decisions must be driven by business risk.

144
MCQhard

During a P1 incident, the crisis management team (CMT) is activated and meets within the first hour. Which communication practice is most appropriate for the CMT to follow when providing updates to the board of directors?

A.Send a brief status report every hour, avoiding speculation and including legal counsel review
B.Provide detailed technical updates every hour
C.Provide speculative root cause analysis to demonstrate competence
D.Wait until the incident is fully understood before any communication
AnswerA

Hourly brief status reports satisfy the board's need for timely assurance during a P1 while avoiding speculation that could create legal or disclosure risk. Legal counsel review ensures privileged, accurate messaging, aligning with crisis communication governance. This balances transparency with containment, meeting the CMT's obligation to inform directors without premature commitment.

Why this answer

During a P1 incident, the CMT must provide timely, concise updates to the board to maintain trust and enable strategic decisions. Option A is correct because it balances frequency (hourly) with content discipline (avoiding speculation) and includes legal counsel review, which is critical for compliance and liability management. This aligns with the CISM Incident Management domain's emphasis on clear, non-technical communication to senior leadership.

Exam trap

The trap here is that candidates confuse the need for technical accuracy with the board's need for strategic clarity, leading them to choose detailed technical updates (Option B) instead of concise, legally vetted status reports.

How to eliminate wrong answers

Option B is wrong because detailed technical updates are inappropriate for the board, which requires high-level impact and status summaries, not technical minutiae like packet captures or system logs. Option C is wrong because speculative root cause analysis can mislead the board, create false confidence, and expose the organization to legal or reputational risk if the actual cause differs. Option D is wrong because waiting until full understanding delays critical communication, leaving the board uninformed and unable to make timely resource or public relations decisions.

145
MCQmedium

A security operations center (SOC) analyst receives an alert indicating that a workstation is communicating with a known command-and-control (C2) server. The analyst confirms the traffic is malicious. According to CISM best practices, which action should the analyst take NEXT?

A.Immediately power off the workstation to stop the C2 communication.
B.Run a full antivirus scan on the workstation to remove the malware.
C.Isolate the workstation from the network and escalate according to the incident response plan.
D.Wait for the next scheduled vulnerability scan to confirm the finding.
AnswerC

Isolating the endpoint from the network stops active C2 communication and potential lateral movement while preserving volatile evidence in memory and existing connections. Escalating per the incident response plan ensures the incident is triaged at the appropriate severity, the right stakeholders are notified, and containment, eradication, and recovery activities proceed in a coordinated and documented manner.

Why this answer

Once malicious C2 traffic is confirmed, the priority is to contain the threat without destroying evidence. Network isolation of the affected endpoint stops ongoing attacker communication and limits lateral movement, while escalation triggers the formal incident response process so that severity, notification, and forensic requirements are handled correctly. Remediation actions such as powering off or scanning the host are premature and can compromise the investigation.

Exam trap

The trap here is assuming that immediately powering off or wiping the infected machine is the fastest way to contain the threat, when doing so actually destroys the volatile evidence needed to understand scope and impact.

146
MCQmedium

An organization has experienced a credential compromise incident. Which playbook should the incident response team primarily use?

A.Data breach playbook
B.Ransomware playbook
C.Credential compromise playbook
D.Insider threat playbook
AnswerC

A credential compromise playbook prescribes the exact sequence for this incident type: revoking active sessions and refresh tokens, forcing password resets, and checking for persistence. Generic playbooks lack these credential-specific steps, so they cannot satisfy the stem's requirement to contain the compromised identity before lateral movement.

Why this answer

Playbooks are tailored to incident types; credential compromise has its own specific playbook.

147
MCQmedium

During a DDoS attack, the incident response team determines that the attack cannot be mitigated within the maximum tolerable downtime (MTD). What should happen next?

A.Notify the board of directors
B.Continue current mitigation efforts
C.Activate business continuity and disaster recovery plans
D.Declare a disaster immediately
AnswerC

When the attack cannot be contained within the maximum tolerable downtime, the incident shifts from response to continuity: activating BC and DR plans restores critical services via alternate arrangements. This satisfies the MTD constraint by prioritising service delivery over attack mitigation.

Why this answer

When a DDoS attack cannot be mitigated within the Maximum Tolerable Downtime (MTD), the organization has exhausted its incident response capability and the outage will exceed the threshold the business can absorb. At that point, the correct action is to transition from incident response to business continuity and disaster recovery (BC/DR) — activating alternate processing sites, failover systems, or manual workarounds to keep critical business functions running. This is the standard escalation path defined in the Business Impact Analysis (BIA) and BC/DR plans.

Exam trap

The trap is choosing 'declare a disaster' or 'notify the board' as the next step — candidates must recognize that the substantive action is BC/DR activation, and that declaration/notification are supporting administrative steps, not the core response.

How to eliminate wrong answers

Option A is wrong because notifying the board is a communication step that may occur in parallel, but it is not the *next* operational action — the board needs to be informed, but the business must first be kept running via BC/DR activation. Option B is wrong because continuing current mitigation efforts when MTD cannot be met means the business will suffer unacceptable downtime; the definition of MTD is the point at which continued response is no longer viable. Option D is wrong because 'declaring a disaster' is a formal declaration that typically triggers BC/DR activation — it is a step within the process, not the substantive action itself, and CISM questions favor the action that directly addresses business continuity over the administrative declaration.

148
MCQeasy

An organization's incident response plan includes a ransomware playbook. After detecting ransomware on a critical server, which of the following should be the FIRST action according to best practices?

A.Notify the CEO and legal counsel before taking any action.
B.Disconnect the server from the network and isolate it.
C.Pay the ransom immediately to regain access.
D.Immediately reboot the server to remove the ransomware.
AnswerB

Isolating the server severs command-and-control and lateral movement paths, halting encryption spread before containment, eradication and recovery proceed. This satisfies the stem's requirement for the first action in the ransomware playbook, since evidence remains intact on the disconnected host.

Why this answer

The immediate priority in ransomware containment is to prevent lateral movement and further encryption of systems. Disconnecting the server from the network (e.g., unplugging the Ethernet cable or disabling the virtual switch port) stops the ransomware from communicating with its command-and-control (C2) server and encrypting additional network shares. This aligns with the NIST SP 800-61 incident response containment strategy, which emphasizes isolation before any other action.

Exam trap

A common pitfall in CISM is believing that notification of executives or legal counsel is the first step in ransomware response. However, the CISM framework prioritizes immediate containment actions like isolation to prevent lateral movement before any communication.

How to eliminate wrong answers

Option A is wrong because notifying the CEO and legal counsel before taking action introduces unnecessary delay, allowing the ransomware to spread further and encrypt more data; notification should occur after containment. Option C is wrong because paying the ransom is not a first action—it is a last-resort business decision that may encourage further attacks and does not guarantee data recovery, and it violates FBI and CISA guidelines. Option D is wrong because rebooting the server can trigger the ransomware to complete its encryption process or delete volume shadow copies, potentially causing permanent data loss and destroying forensic evidence.

149
MCQhard

Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?

A.Implement a change management process to prevent unauthorized configuration changes
B.Update the firewall rule base immediately
C.Conduct a vulnerability scan on all firewalls
D.Disconnect the firewall from the network
AnswerA

The 5 Whys exposed a governance gap: unauthorised firewall configuration changes were possible. Change management enforces approval, testing and documentation for configuration alterations, directly addressing that root cause. Patching or monitoring alone would not prevent recurrence of the underlying control weakness.

Why this answer

Root cause analysis should uncover not just technical causes but also the process and governance failures that allowed the misconfiguration. Addressing the management failure (e.g., inadequate change management) provides a systemic fix.

150
Multi-Selectmedium

An organization's incident response team is reviewing its post-incident activities after resolving a significant security incident. Management wants to ensure lessons learned are captured and that the response capability improves over time. Which TWO of the following activities are MOST important to include in the post-incident phase? (Choose two.)

Select 2 answers
A.Immediately close the incident ticket and archive all communications to reduce administrative overhead.
B.Conduct a structured lessons-learned review with responders and stakeholders to identify gaps and assign improvement actions.
C.Terminate all personnel who were involved in the incident response to reinforce accountability.
D.Update incident response plans, playbooks, and contact lists based on validated findings from the incident.
E.Publicly disclose full technical details of the incident to demonstrate transparency to competitors.
AnswersB, D

A structured lessons-learned review captures what worked and what failed while details are fresh, and converting findings into assigned improvement actions ensures the organization actually changes. Without this step, the same weaknesses recur in future incidents. Including both responders and stakeholders broadens perspective, covering technical, process, and communication gaps, and produces prioritized remediation items with owners and due dates.

Why this answer

The post-incident phase exists to convert experience into improved capability. A structured lessons-learned review surfaces technical, procedural, and communication gaps and converts them into assigned corrective actions. Updating plans, playbooks, and contact lists based on validated findings ensures those improvements are institutionalized and available for the next event.

Together, these activities close the improvement loop and build a more resilient response capability over time.

Exam trap

The trap here is equating post-incident work with administrative closure or punitive action, when its real purpose is structured learning and updating response documentation based on validated findings.

← PreviousPage 2 of 3 · 190 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Incident Management questions.