Courseiva

CCNA Incident Management Questions

40 of 190 questions · Page 3/3 · Incident Management · Answers revealed

151
Multi-Selectmedium

Which TWO of the following are essential components of an incident response programme?

Select 2 answers
A.Incident response plan
B.Incident response policy
C.Annual penetration test
D.Vulnerability scanning schedule
E.Security awareness training
AnswersA, B

The incident response plan is an essential programme component, defining scope, roles, escalation paths, communication procedures and response phases. Without it, teams lack a coordinated, repeatable approach to detecting, containing and recovering from incidents, undermining the entire programme's effectiveness.

Why this answer

An incident response plan (A) is essential because it defines the documented, step-by-step procedures, roles, communication paths, and escalation criteria that guide the team through detecting, containing, eradicating, and recovering from a security incident. An incident response policy (B) is equally essential because it is the governing document that establishes the organization's mandate, scope, objectives, authority, and management commitment for incident handling, which the plan then implements. Together, the policy provides the 'why and who' while the plan provides the 'how and when,' forming the foundational pair of any incident response programme.

By contrast, an annual penetration test (C) and a vulnerability scanning schedule (D) are proactive vulnerability-management activities that feed the programme but are not core structural components of it, and security awareness training (E) is a preventive control that supports the programme rather than constituting an essential incident response component.

152
MCQmedium

During a major incident, the incident response team discovers that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

A.Continue incident response efforts until resolution regardless of time
B.Declare the incident a disaster and shut down all systems
C.Notify the insurance provider immediately
D.Escalate to activate the business continuity and disaster recovery plans
AnswerD

Exceeding the maximum tolerable downtime means recovery within the primary environment is no longer viable, so escalating to activate business continuity and disaster recovery plans restores critical services through alternate arrangements. This directly satisfies the MTD constraint.

Why this answer

When an incident cannot be resolved within the MTD, it triggers the transition to business continuity and disaster recovery (BC/DR) plans to maintain critical operations.

153
MCQmedium

During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?

A.Incident response manager
B.Security analyst
C.Forensic investigator
D.Communications lead
AnswerA

The incident response manager owns end-to-end coordination of the P1 response, directing technical teams while acting as the single conduit for executive updates, which satisfies the stem's requirement for both overall coordination and timely leadership communication.

Why this answer

In a P1 ransomware incident, the incident response manager (IRM) is responsible for orchestrating the overall response, prioritizing containment over eradication, and ensuring that executive leadership receives timely, accurate status updates. Unlike technical roles, the IRM owns the incident command structure, coordinates cross-functional teams, and manages communication escalations to stakeholders, which is critical when encrypted servers demand immediate business continuity decisions.

Exam trap

CISM exam often tests the distinction between tactical roles (security analyst, forensic investigator) and the strategic coordination role (incident response manager). Candidates may mistakenly choose the communications lead because they confuse 'communication to executives' with the overall coordination responsibility, but the IRM owns the overall incident command structure.

How to eliminate wrong answers

Option B (Security analyst) is wrong because a security analyst focuses on technical triage, log analysis, and initial containment actions, not on coordinating the overall response or communicating with executives. Option C (Forensic investigator) is wrong because a forensic investigator is responsible for preserving evidence and performing root-cause analysis, not for managing the incident response lifecycle or executive updates. Option D (Communications lead) is wrong because while the communications lead handles external and internal messaging, they do not own the overall response coordination; they report to the incident response manager who retains strategic authority.

154
MCQmedium

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the relevant supervisory authority?

A.72 hours
B.48 hours
C.24 hours
D.96 hours
AnswerA

Under Article 33 of the GDPR, a controller must notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. This strict deadline applies specifically because the breach involves EU residents’ personal data, triggering the GDPR’s territorial and material scope. The 72-hour window is the maximum statutory period, not a recommended target, and failure to comply can result in administrative fines under Article 83.

Why this answer

GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms.

155
MCQeasy

A multinational company experiences a ransomware attack that encrypts critical servers in its European and North American data centers. The incident response team has contained the spread, but restoration will take several days. Executive leadership asks the CISO what should be done to manage the business impact while recovery proceeds. Which of the following is the MOST appropriate immediate action?

A.Shut down all remaining systems to prevent any further encryption, even those not yet affected.
B.Pay the ransom immediately to shorten the recovery time and reduce business disruption.
C.Wait until all servers are fully restored before informing customers or business partners.
D.Activate the business continuity and disaster recovery plans to maintain critical business functions.
AnswerD

Activating business continuity and disaster recovery plans allows the organization to maintain or restore critical functions while systems are recovered. This directly addresses the business impact of a multi-day outage and aligns with CISM guidance that incident management must integrate with continuity and recovery capabilities. It is the most appropriate immediate action to keep essential operations running during restoration.

Why this answer

When a ransomware attack causes a multi-day outage, the priority is to maintain critical business functions through business continuity and disaster recovery plans. Containment has already been achieved, so the focus shifts to minimizing business impact while restoring systems. Continuity activation supports customers, partners, and revenue streams, and it integrates with incident response to manage the overall event.

Exam trap

The trap here is treating ransomware purely as a technical recovery problem, when the immediate executive concern is maintaining business operations through continuity planning.

156
MCQmedium

During containment of a confirmed intrusion, the incident response manager must decide whether to immediately rebuild the compromised server or first acquire volatile data. Legal counsel has signalled that litigation is likely. Which of the following is the BEST course of action?

A.Capture volatile data in order of volatility, then rebuild the server from a known-good image
B.Rebuild the server immediately to restore service, then document what was observed before the rebuild
C.Leave the server running untouched until the external forensic firm arrives several days later
D.Shut down the server immediately to preserve its current state for investigators
AnswerA

Volatile artefacts disappear on shutdown, so they must be collected first, following the order-of-volatility principle. Once memory, connections, and process state are preserved, the server can be rebuilt from trusted media to restore service. This satisfies both the forensic and legal requirements and the business need to recover, which is the balanced outcome the scenario demands.

Why this answer

Forensic soundness requires capturing the most volatile data first because memory and connection state are lost on shutdown or rebuild. Once that evidence is preserved, the server can be rebuilt from a known-good image to restore service. This sequence respects the litigation hold implied by legal counsel while still meeting the organisation's recovery objectives.

Exam trap

The trap here is treating evidence preservation and service restoration as mutually exclusive, when the correct sequence is to capture volatile data first and then rebuild.

157
MCQeasy

An organization has just experienced a data breach involving customer personal information. The incident manager is determining the appropriate communication strategy. Which action BEST aligns with CISM incident management practices?

A.Coordinate with legal counsel and communications to notify affected parties and regulators as required.
B.Notify only the customers who are likely to complain, to minimize business disruption.
C.Publicly disclose all technical details of the breach immediately to demonstrate transparency.
D.Delay all notifications until the forensic investigation is completely finished, regardless of regulatory deadlines.
AnswerA

CISM emphasizes that breach communication must be coordinated with legal counsel and communications teams to ensure regulatory notifications and customer messaging are accurate, timely, and compliant. This approach balances transparency with legal obligations and reputational management. It is the best action because it follows a structured, stakeholder-informed process rather than unilateral or premature disclosure.

Why this answer

Breach communication should be coordinated with legal counsel and communications to ensure regulatory notifications and customer messaging are timely, accurate, and compliant. Premature public disclosure, indefinite delay, and selective notification all fail to meet CISM expectations for structured, legally sound, and ethical incident communication.

Exam trap

The trap here is equating transparency with immediate full technical disclosure, when CISM expects coordinated, legally reviewed communication.

158
MCQmedium

Which of the following is the PRIMARY reason to include legal counsel in the incident response team?

A.To communicate with the media
B.To authorize technical containment actions
C.To advise on legal obligations and protect privilege
D.To manage technical aspects of the investigation
AnswerC

Legal counsel advises on statutory notification duties and preserves attorney–client privilege over breach findings, satisfying the stem's demand for the primary reason. Privilege protection prevents compelled disclosure of incident assessments, while regulatory expertise ensures timely compliance with breach reporting deadlines.

Why this answer

Legal counsel ensures that actions taken during an incident preserve attorney-client privilege and comply with legal obligations, such as breach notification and litigation holds.

159
MCQeasy

Which of the following is the primary purpose of having a pre-established forensic retainer agreement?

A.To reduce the time required to engage external forensics during an incident
B.To ensure the forensics firm is certified
C.To guarantee the lowest price for forensic services
D.To comply with regulatory requirements
AnswerA

A retainer pre-negotiates rates, scope, contacts and legal terms with a forensics provider, so engagement begins immediately when an incident occurs. This removes procurement and contracting delays, directly reducing the time required to engage external forensics and preserving volatile evidence.

Why this answer

A pre-established retainer reduces the time to engage a forensics firm during an incident, ensuring rapid response.

160
MCQmedium

During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?

A.Include speculative root causes to show thoroughness
B.Wait until the incident is fully resolved before communicating
C.Send hourly situation reports (sitreps) focusing on business impact and key actions
D.Provide detailed technical analysis in every update
AnswerC

Hourly sitreps satisfy the P1 escalation cadence executives require during ransomware, prioritising business impact and key actions over technical forensics. This keeps decision-makers informed on service disruption, containment progress and recovery timelines without overwhelming them with indicators of compromise, preserving their ability to authorise business-continuity and communication decisions.

Why this answer

For critical incidents, hourly sitreps (situation reports) are recommended to keep executives informed. Avoiding speculation and preserving legal privilege with counsel involvement are also key.

161
MCQmedium

During a major cybersecurity incident, the incident response team determines that the incident cannot be resolved within the maximum tolerable downtime (MTD). Which of the following actions should be taken next?

A.Conduct a root cause analysis
B.Declare a disaster and activate the BC/DR plan
C.Notify the executive sponsor and continue response efforts
D.Increase the number of incident responders
AnswerB

Declaring a disaster activates the BC/DR plan, which provides pre-approved recovery strategies, resource allocation and escalation paths when MTD cannot be met. The MTD breach is the trigger criterion; the BC/DR plan exists precisely to restore critical services beyond normal incident response capabilities, ensuring business continuity within recovery objectives.

Why this answer

When an incident cannot be resolved within the MTD, the organization has exceeded its tolerance for downtime, which qualifies as a disaster. The next step is to declare a disaster and activate the Business Continuity/Disaster Recovery (BC/DR) plan to restore critical operations through alternate means.

Exam trap

CISM often tests the confusion between incident response escalation and disaster declaration — candidates pick 'notify executives' when the correct trigger is MTD breach, which mandates BC/DR activation.

How to eliminate wrong answers

Option A is wrong because root cause analysis is a post-incident activity performed after service is restored; it does not address the immediate need to recover operations. Option C is wrong because notifying the executive sponsor and continuing response efforts does not address the fact that MTD has been exceeded — escalation without activating BC/DR leaves the business exposed. Option D is wrong because adding responders does not change the fact that the incident cannot be resolved within MTD; it may help but does not trigger the necessary BC/DR activation.

162
Multi-Selecthard

An organisation is reviewing its incident response capabilities after a near-miss. The CISO wants to ensure the team can effectively detect and respond to future incidents. Which TWO of the following are the MOST important capabilities to establish before an incident occurs? (Choose two.)

Select 2 answers
A.A full forensic laboratory with hardware write blockers and analysis workstations.
B.A documented incident response plan with defined roles, responsibilities, and escalation paths.
C.Trained incident response personnel with clearly defined on-call responsibilities.
D.A cyber insurance policy covering incident response costs and regulatory fines.
E.A public relations firm on retainer to manage media inquiries during incidents.
AnswersB, C

A documented plan provides the structure responders rely on when an incident occurs, defining who does what and how events escalate. Without it, response becomes ad hoc, delayed, and inconsistent, increasing impact. CISM treats the incident response plan as a foundational control that should be approved by management, communicated to stakeholders, and tested regularly. It also supports regulatory expectations for demonstrable preparedness and gives the CISO a basis for measuring and improving response capability.

Why this answer

Effective incident response before an incident occurs depends on two foundational capabilities: a documented plan that defines roles, responsibilities, and escalation, and trained personnel with clear on-call accountability. These elements enable timely detection follow-through, containment, and coordinated recovery. Public relations retainers, forensic laboratories, and cyber insurance are supporting or risk-transfer measures that do not by themselves create response capability, and they cannot substitute for planning and skilled people when an incident actually occurs.

Exam trap

The trap here is choosing supporting resources such as insurance or a forensic lab as primary capabilities, when the essential foundation is a documented plan and trained, accountable responders.

163
MCQmedium

An organization's incident response plan requires that evidence be collected in a forensically sound manner. A responder is about to capture volatile data from a compromised server. Which action BEST preserves the integrity of the evidence?

A.Run a full antivirus scan and allow it to quarantine any detected threats before collecting data.
B.Reboot the server first to clear any malicious processes before collecting data.
C.Immediately power off the server and store the hard drive in a secure location.
D.Document the system state, capture volatile data in order of volatility, and maintain a chain of custody.
AnswerD

Forensically sound collection follows the order of volatility, starting with the most perishable data such as memory and network connections, then moving to disk. Documenting the state and maintaining a chain of custody ensures evidence integrity and admissibility. This approach aligns with CISM guidance to preserve evidence properly while supporting incident analysis and any subsequent legal or regulatory actions.

Why this answer

Sound forensic collection follows the order of volatility, capturing memory and network state before disk, while documenting actions and maintaining chain of custody. Rebooting, powering off, or running antivirus modifies or destroys evidence. CISM stresses that evidence must be preserved in a manner that supports both incident analysis and potential legal or regulatory proceedings.

Exam trap

The trap here is treating remediation steps such as rebooting or antivirus scanning as compatible with evidence preservation, when they actually destroy or alter it.

164
Multi-Selectmedium

Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?

Select 2 answers
A.Restoring backups of affected servers
B.Approving external communications and public statements
C.Analyzing log files to identify the attack vector
D.Conducting technical forensic analysis of compromised systems
E.Making strategic decisions about business continuity activation
AnswersB, E

The CMT owns reputational and stakeholder impact, so it approves external communications and public statements, ensuring legal, regulatory and messaging consistency. This satisfies the stem by keeping disclosure decisions at strategic level rather than with technical responders, who lack authority to commit the organisation publicly.

Why this answer

Option B is correct because the crisis management team owns the incident's external-facing messaging, ensuring that all press releases, customer notifications, and regulatory disclosures are reviewed and approved before release to protect the organization's reputation and legal standing. Option E is correct because the CMT is a strategic decision-making body that determines whether to invoke business continuity or disaster recovery plans, weighing operational impact, safety, and financial consequences rather than performing hands-on technical work. Options A, C, and D are incorrect because restoring backups, analyzing logs to find the attack vector, and conducting forensic analysis of compromised systems are tactical, technical tasks performed by incident response handlers, forensic analysts, and system administrators, not by the strategic CMT.

Exam trap

The trap here is confusing the strategic responsibilities of the CMT with the tactical or operational tasks of the technical incident response team, leading candidates to select hands-on actions like log analysis or backup restoration instead of high-level decision-making roles.

165
MCQhard

During a major ransomware incident, the chief information security officer (CISO) must decide whether to pay the ransom to restore encrypted clinical trial data at a pharmaceutical company. The attackers have threatened to publish the data if not paid within 48 hours. Which of the following is the MOST important factor for the CISO to consider when making this business decision?

A.Whether the organization has a validated, tested backup and recovery capability that can restore the data without paying.
B.Whether the attackers have provided a decryption tool that works on a sample file.
C.Whether the attackers have a reputation for honoring their promises in previous incidents.
D.Whether the organization has a cyber insurance policy that will reimburse the ransom payment.
AnswerA

The existence of validated, tested backups determines whether the organization can recover without funding criminals and without relying on the attackers' promises. This is the most important factor because it directly affects business continuity, data integrity, and the organization's negotiating position. If backups are reliable, payment becomes unnecessary; if they are not, the CISO must weigh residual risk and legal implications. This aligns with CISM's emphasis on resilience and risk-based decision making.

Why this answer

A validated and tested backup and recovery capability is the most important factor because it determines whether the organization can restore operations without paying and without trusting the attacker. It directly supports business continuity and reduces the organization's dependence on criminal actors. Insurance, sample decryptors, and attacker reputation are secondary or unreliable considerations that do not resolve the core recovery and risk question.

Exam trap

The trap here is focusing on the mechanics of payment, such as insurance coverage or a working sample decryptor, rather than on the organization's own ability to recover without paying.

166
Multi-Selectmedium

Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)

Select 2 answers
A.Vendor risk assessment reports
B.Detailed network architecture diagrams
C.Communication templates
D.Playbook for ransomware incidents
E.IR team roster and contact list
AnswersC, E

Pre-approved communication templates let the IR team notify stakeholders, regulators and customers quickly and consistently during a high-pressure incident, satisfying the plan's requirement for defined escalation and messaging procedures rather than improvising statements under time pressure.

Why this answer

Communication templates (C) are an essential IR plan component because during an incident responders must notify stakeholders, legal, regulators, and customers quickly and consistently, and pre-approved templates prevent delays and wording errors under pressure. The IR team roster and contact list (E) is also essential because the plan must identify who is on the incident response team and how to reach them (including after-hours and escalation contacts) so the team can be assembled immediately. Detailed network architecture diagrams (B) and vendor risk assessment reports (A) are valuable supporting artifacts for preparation and investigation, but they are not core components of the IR plan itself.

A ransomware playbook (D) is a useful specialized procedure, yet it is only one scenario-specific playbook rather than a foundational element required in every IR plan.

167
MCQeasy

An organisation has just completed recovery from a significant cybersecurity incident. The CISO wants to ensure the lessons learned are captured and used to improve future response. Which of the following should be performed as part of the post-incident activity?

A.Publish a press release describing the incident and the organisation's response.
B.Conduct a post-incident review with key stakeholders to identify root cause and improvement actions.
C.Immediately close the incident ticket and return the team to normal duties.
D.Update the risk register only if the incident resulted in a regulatory fine.
AnswerB

A post-incident review brings together the responders and business stakeholders to examine what happened, why it happened, and what should change. It produces documented improvement actions that feed back into the incident response plan, controls, and training. CISM treats this feedback loop as essential to maturing the incident management capability. Without a structured review, the organisation risks repeating the same failures and cannot demonstrate due diligence to regulators or auditors.

Why this answer

Post-incident activity in CISM is about converting experience into improvement. A structured review with key stakeholders identifies root cause, evaluates the effectiveness of the response, and generates corrective actions that update plans, controls, and training. Closing the ticket, waiting for a fine, or issuing a press release do not build organisational capability.

The review ensures the incident response programme evolves and that lessons are documented for future reference and audit.

Exam trap

The trap here is equating incident closure or public communication with lesson learning, when the essential post-incident step is a structured review that produces improvement actions.

168
Multi-Selectmedium

Which TWO of the following are essential components of an incident response plan? (Select two.)

Select 2 answers
A.Communication templates
B.Vendor risk assessment reports
C.IR team roster and contact list
D.Network architecture diagrams
E.Annual security awareness training schedule
AnswersA, C

Communication templates satisfy the stakeholder-notification constraint by pre-drafting regulatory, legal and executive messaging, so notifications occur within mandated breach-reporting windows rather than being composed under pressure. They also standardise severity-dependent escalation paths, ensuring consistent disclosure across jurisdictions and preventing inadvertent admission of liability during Microsoft Entra ID compromise investigations.

Why this answer

Option A (Communication templates) is correct because an incident response plan must include pre-approved notification templates for internal stakeholders, customers, regulators, and media so that accurate, consistent messaging can be delivered quickly during a live incident without drafting communications under pressure. Option C (IR team roster and contact list) is correct because the plan must identify who is on the incident response team, their roles (e.g., incident commander, forensics lead, communications lead), and up-to-date 24/7 contact details so the team can be assembled immediately when an incident is declared. The remaining options are supporting or program-level artifacts rather than essential plan components: vendor risk assessment reports (B) belong to third-party risk management, network architecture diagrams (D) are useful reference documentation but not a required element of the plan itself, and an annual security awareness training schedule (E) is part of the broader security awareness program, not the incident response plan.

169
MCQhard

A financial services firm has just contained a malware outbreak that disabled online banking for six hours. The incident commander confirms systems are restored and monitoring is stable. Executive leadership now wants to know what must happen before the incident can be formally closed. Which activity is MOST important to complete prior to closure?

A.Notify the regulator a second time to confirm that online banking services have been fully restored
B.Conduct a lessons-learned review to identify improvements to the incident response plan and controls
C.Purchase additional endpoint detection licenses to cover the remaining unmanaged devices
D.Rotate all administrative credentials and reimage every server in the affected data center
AnswerB

A lessons-learned review converts the incident into durable improvement by examining what worked, what failed, and which controls, procedures, or training need change. CISM treats post-incident review as the mechanism that closes the loop between response and prevention, ensuring the same weakness is not exploited again. Without it, the organization returns to its prior state and repeats mistakes. It is the defining pre-closure activity because it captures organizational learning while details remain fresh.

Why this answer

Formal incident closure requires more than restored service; it requires capturing what happened and improving from it. The lessons-learned review examines detection, response, and control effectiveness, producing corrective actions that reduce recurrence likelihood and severity. Tool purchases, additional notifications, and blanket reimaging are either premature, situationally dependent, or duplicative of completed recovery work.

By institutionalizing findings before closure, the organization ensures the incident yields lasting security value rather than a return to the status quo.

Exam trap

The trap here is equating containment and restoration with incident closure, when the post-incident lessons-learned review is what formally completes the lifecycle.

170
MCQhard

During a post-incident root cause analysis, the team uses the '5 Whys' technique and identifies a technical vulnerability as the cause. According to CISM best practices, what should be the NEXT level of analysis?

A.Determine the process failure that allowed the vulnerability to go unaddressed.
B.Immediately patch the vulnerability and move on.
C.Escalate the issue to the vendor for a software fix.
D.Identify the specific employee responsible for the vulnerability.
AnswerA

A technical vulnerability is a symptom; CISM root cause analysis must progress to the management system. Determining which process failed to identify, assess, or remediate that vulnerability addresses the underlying governance weakness, preventing recurrence rather than merely patching one flaw.

Why this answer

The '5 Whys' should drill deeper to uncover process and management failures that allowed the technical vulnerability to exist.

171
MCQmedium

Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?

A.Report IoCs to law enforcement only.
B.Share IoCs with industry peers via the relevant ISAC.
C.Keep IoCs confidential to protect the organization's reputation.
D.Publish IoCs on the organization's public website.
AnswerB

An ISAC provides a trusted, sector-specific sharing channel with anonymisation and legal protections, letting peers block the same indicators quickly. This satisfies the stem's need for the best sharing approach, since public disclosure risks tipping off the attacker and exposing the victim.

Why this answer

Sharing IoCs with an ISAC (Information Sharing and Analysis Center) helps the broader community defend against similar attacks, which is a key post-incident activity.

172
MCQeasy

Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?

A.Chief executive officer (CEO)
B.Security operations center (SOC) analyst
C.Help desk manager
D.External forensics investigator
AnswerA

The CEO sits on the crisis management team because major incidents demand strategic decisions on business continuity, regulatory disclosure, and resource authorisation that exceed operational authority. Their presence satisfies the stem's requirement for executive-level command during a major cybersecurity incident.

Why this answer

The CMT includes senior leaders such as the CEO, CFO, CISO, General Counsel, and Communications head to handle strategic decisions and external communications.

173
Multi-Selectmedium

An organization is updating its incident response plan. Which TWO components are essential to include for effective insider threat management? (Select TWO.)

Select 2 answers
A.A dedicated ransomware recovery procedure.
B.Procedures for coordinating with human resources and legal departments.
C.A list of all employee passwords for investigation purposes.
D.A playbook specifically for insider threat scenarios.
E.Contact information for the DDoS mitigation service provider.
AnswersB, D

Insider cases typically end in disciplinary or criminal proceedings, so the plan must define how IR liaises with HR and legal. This coordination preserves evidence integrity, satisfies employment law obligations and ensures sanctions are lawfully applied rather than handled unilaterally by the security team.

Why this answer

Option B is correct because insider threat incidents require close coordination with human resources and legal departments to handle employee privacy, employment law, evidence handling, and potential disciplinary or legal action properly. Option D is correct because a dedicated insider threat playbook provides specific, pre-defined procedures for detecting, investigating, and responding to malicious or negligent insider activity, which differs from generic incident response steps. Option A is not essential here because ransomware recovery is a separate threat category and does not specifically address insider threat management.

Option C is inappropriate and insecure because storing all employee passwords violates least privilege and credential security best practices. Option E is unrelated because DDoS mitigation contacts address external availability attacks, not insider threats.

Exam trap

CISM often tests the confusion between general incident response components and insider-threat-specific requirements — candidates may pick ransomware or DDoS procedures because they sound like incident response, but the question specifically asks for insider threat management essentials.

174
MCQmedium

An organization's incident response plan defines communication procedures, but during a recent incident, customers learned about a data breach from media reports before receiving any notification from the company. The information security manager has been asked to address this gap. Which of the following is the MOST effective improvement?

A.Pre-drafting notification templates and defining approval workflows with legal, communications, and executive stakeholders
B.Requiring all employees to sign an updated nondisclosure agreement covering incident details
C.Publishing the full incident response plan on the corporate website to demonstrate transparency
D.Adding a public relations representative to the technical incident response team
AnswerA

Pre-approved templates and defined approval paths remove the delays and ambiguity that allow rumors or media to outpace official communication. By aligning legal, communications, and executives in advance, the organization can issue accurate, timely notifications within regulatory windows and preserve stakeholder trust. This directly addresses the gap of customers hearing from media first.

Why this answer

When customers learn of a breach from media before official notice, the root cause is usually slow or undefined notification workflow. Pre-drafted templates plus agreed approval paths among legal, communications, and executives compress the time from confirmation to notification, ensuring the organization controls the narrative and meets regulatory deadlines. The other options either target unrelated risks or only partially address the coordination gap.

Exam trap

The trap here is reaching for confidentiality controls or public transparency when the real failure is an unprepared, slow notification workflow among legal, communications, and executives.

175
Multi-Selectmedium

Which THREE of the following are typical roles in an incident response team? (Select THREE)

Select 3 answers
A.IR manager
B.Human resources representative
C.Forensic investigators
D.Security analysts
E.Internal audit representative
AnswersA, C, D

The IR manager owns and directs the response, coordinating the team, making escalation decisions and liaising with executives and the crisis management team. This command-and-control function is a standard, defined role in any incident response structure.

Why this answer

The IR manager (A) is a core role that coordinates the entire incident response effort, making decisions on escalation, communication, and resource allocation during an incident. Forensic investigators (C) are essential for collecting, preserving, and analyzing evidence such as disk images, memory dumps, and logs to determine the scope and root cause of a breach. Security analysts (D) form the frontline technical role, monitoring SIEM alerts, triaging events, and performing initial containment and eradication actions.

Human resources (B) and internal audit (E) may be consulted for employee-related or compliance matters, but they are supporting stakeholders rather than typical standing roles within the incident response team itself.

176
MCQeasy

An organization has just experienced a malware outbreak that was contained by isolating affected endpoints. Before restoring the isolated systems to normal operation, the incident response team must decide what activity comes next in the response lifecycle. Which of the following should the team perform NEXT?

A.Conduct a full lessons-learned review and close the incident as resolved.
B.Begin recovery by reconnecting all isolated endpoints to the production network immediately.
C.Eradicate the malware and remediate the root cause on affected systems before returning them to production.
D.Notify external regulators and law enforcement before any technical remediation is attempted.
AnswerC

After containment, the next phase is eradication, which removes the malicious code, closes the initial access vector, and remediates the underlying weakness. Returning systems to production before eradication risks immediate reinfection. Eradication may include reimaging, patching, credential resets, and removing persistence mechanisms, and it must be verified before recovery begins so that restored systems are clean and stable.

Why this answer

The incident response lifecycle moves from preparation to detection and analysis, containment, eradication, recovery, and post-incident activity. Once containment has stopped the spread, the team must eradicate the malware and remediate the root cause before systems are returned to production. Recovery without eradication invites reinfection, while review and notification are either parallel obligations or later-phase activities.

Eradication is the logical next technical step.

Exam trap

The trap here is assuming that containment equals resolution, when containment merely stops the spread and eradication must occur before recovery or incident closure.

177
MCQhard

A security manager is reviewing the organization's incident response capabilities. During a tabletop exercise, participants struggled to determine who has authority to shut down a critical production system during a suspected incident. Which action BEST addresses this gap?

A.Require all incident responders to obtain a forensic certification before the next exercise
B.Increase the frequency of technical vulnerability scans on the critical production system
C.Implement an automated tool that shuts down production systems when malware is detected
D.Document and communicate clear decision-making authority and escalation paths in the incident response plan
AnswerD

The exercise exposed uncertainty about who can authorize a disruptive action, which is a governance gap. Clearly documented authority, thresholds, and escalation paths remove ambiguity and speed decision-making during real incidents. CISM emphasizes that incident response plans must define roles, responsibilities, and decision rights in advance. This directly addresses the identified weakness and improves response effectiveness.

Why this answer

The tabletop exercise revealed that the organization lacks clarity on decision-making authority during incidents. The most effective remedy is to define and communicate who can make high-impact decisions, such as shutting down production, and under what conditions. Documenting escalation paths ensures that responders know when and to whom to escalate.

Technical controls and additional certifications do not resolve governance ambiguity, which is the root cause of the observed struggle.

Exam trap

The trap here is treating a governance gap revealed by an exercise as a technical or training problem, rather than fixing the underlying decision-rights ambiguity.

178
MCQhard

During a major cybersecurity incident, the crisis management team (CMT) has been activated. Which of the following is the PRIMARY responsibility of the CEO as a member of the CMT?

A.Authorizing external communications and resource allocation
B.Updating the incident response playbook
C.Directing the technical containment efforts
D.Conducting forensic analysis of affected systems
AnswerA

The CEO holds ultimate authority to approve external communications and commit organisational resources, which no other CMT member can exercise. This satisfies the stem's requirement for the CEO's primary responsibility during an activated crisis management team.

Why this answer

The CEO provides strategic direction and approves major decisions, such as activating business continuity or communicating externally, while the CISO leads the technical response.

179
MCQhard

A financial services firm has completed containment and eradication of a sophisticated intrusion. The incident response team is now preparing for the post-incident phase. The CISO asks what activity will BEST reduce the likelihood of a similar incident recurring. Which activity should be prioritized?

A.Conducting a lessons-learned review with all stakeholders and updating the incident response plan and security controls based on findings.
B.Increasing the security operations center (SOC) monitoring hours to provide 24/7 coverage.
C.Purchasing additional cyber insurance coverage to transfer more of the financial risk from future incidents.
D.Terminating the employees whose accounts were compromised during the incident.
AnswerA

A structured lessons-learned review identifies gaps in detection, response, and controls, and translates them into concrete improvements to the incident response plan and security architecture. This is the core of the post-incident phase in CISM and directly reduces the likelihood of recurrence by fixing root causes and process weaknesses. Involving all stakeholders ensures that technical, legal, and business perspectives are captured. The resulting updates make the organization more resilient for future incidents.

Why this answer

The post-incident lessons-learned review is the activity that best reduces recurrence because it identifies what failed, why, and what must change in the incident response plan and security controls. It converts the experience into actionable improvements across people, process, and technology. Insurance, extended monitoring hours, and personnel termination do not directly fix the root causes and may misdirect resources away from the actual weaknesses.

Exam trap

The trap here is choosing a risk transfer or broad operational measure, such as insurance or longer monitoring hours, instead of the root-cause-driven lessons-learned review that actually prevents recurrence.

180
MCQhard

During a major data breach investigation, legal counsel advises the incident response team to preserve attorney-client privilege over communications with external forensic investigators. Which of the following actions BEST supports this objective?

A.Have all communications with the forensic firm go through the CISO.
B.Avoid documenting any findings related to the breach until after litigation is resolved.
C.Ensure the forensic engagement letter includes a clause acknowledging attorney-client privilege.
D.Direct the forensic investigators to report to legal counsel and mark all deliverables as privileged.
AnswerD

Routing forensic work through legal counsel and marking deliverables privileged brings the investigation under attorney work product, shielding it from disclosure. This satisfies the privilege-preservation objective by establishing counsel as the directing client rather than the incident response team.

Why this answer

Directing forensic investigators to report directly to legal counsel and marking all deliverables as privileged establishes a clear legal framework for attorney-client privilege. This ensures that communications and work product are protected from discovery in litigation, as they are created under the direction of legal counsel for the purpose of providing legal advice.

Exam trap

A common misconception is that a contractual clause or routing through a senior executive (like the CISO) is sufficient to preserve privilege, when in fact the legal control and direction by counsel is the critical factor.

How to eliminate wrong answers

Option A is wrong because having all communications go through the CISO does not automatically create attorney-client privilege; the CISO is a technical role, not legal counsel, and such communications may be deemed business communications rather than privileged legal advice. Option B is wrong because avoiding documentation of findings violates standard incident response best practices and may lead to spoliation of evidence, which can result in legal sanctions; privilege does not require destruction of evidence. Option C is wrong because a clause in the engagement letter acknowledging privilege is insufficient; privilege is determined by the actual control and purpose of the work, not merely a contractual statement, and without legal counsel directing the work, the clause may be disregarded by a court.

181
Multi-Selectmedium

An organization is reviewing its incident response plan after a tabletop exercise revealed confusion about roles during a major incident. The CISO wants to clarify which activities belong to the incident response team versus the crisis management team. Which TWO of the following activities are PRIMARY responsibilities of the crisis management team during a major incident? (Choose two.)

Select 2 answers
A.Authorizing the expenditure of emergency funds to engage external counsel and forensic vendors.
B.Performing forensic imaging of compromised servers to preserve evidence.
C.Analyzing malware samples to determine the attacker's command-and-control infrastructure.
D.Approving strategic communications to customers, regulators, and the media.
E.Configuring firewall rules to block identified malicious IP addresses.
AnswersA, D

Authorizing emergency expenditure is a strategic, fiduciary decision that sits with the crisis management team because it involves significant cost and enterprise risk. Engaging external counsel and forensic firms often requires executive approval beyond normal procurement thresholds. The CMT balances the financial impact against the need for rapid expert support. This is a governance responsibility that enables the technical response rather than executing it.

Why this answer

The crisis management team owns strategic decisions such as approving external communications and authorizing emergency spending for legal and forensic support. These activities require executive authority and affect the entire enterprise. Forensic imaging, malware analysis, and firewall changes are tactical tasks belonging to the incident response team and should remain with technical responders to keep the CMT focused on governance and business impact.

Exam trap

The trap here is equating the crisis management team with the incident response team, leading to the selection of hands-on technical tasks as CMT responsibilities.

182
MCQeasy

What is the recommended timeframe for holding a lessons learned meeting after an incident has been resolved?

A.Within 2 weeks
B.Within 1 month
C.Within 3 months
D.Within 24 hours
AnswerA

Holding the meeting within two weeks captures recollections while still fresh, before details fade, yet allows enough time to gather evidence and complete initial investigation. Longer delays erode accuracy and weaken the corrective actions derived.

Why this answer

A lessons learned meeting is most effective when held within 2 weeks of incident resolution, while details are still fresh in participants' memories but after immediate recovery pressures have subsided. This window allows time to gather facts, review logs, and prepare meaningful discussion points without losing critical context. CISM best practice emphasizes timely but not rushed post-incident reviews to capture actionable improvements.

Exam trap

CISM often tests the tension between speed and thoroughness in post-incident activities — candidates who equate 'sooner is always better' incorrectly select 24 hours, while those who prioritize completeness over timeliness select 1 month.

How to eliminate wrong answers

Option B is wrong because waiting up to 1 month allows memory decay and staff reassignment, reducing the accuracy and value of the review. Option C is wrong because 3 months is far too long — key personnel may have moved on and technical details will be lost, making the review largely ineffective. Option D is wrong because 24 hours is too soon; the team is still in recovery mode, facts are incomplete, and a rushed meeting produces superficial findings rather than meaningful lessons.

183
MCQeasy

An organization has just completed its response to a significant security incident. The information security manager is preparing the post-incident review and wants to ensure the effort produces lasting improvement rather than a one-time report. Which of the following activities is MOST important to include in the post-incident review?

A.Distributing a detailed technical timeline of the attacker's activity to all employees
B.Calculating the total cost of the incident to present to the board of directors
C.Documenting lessons learned and assigning owners and due dates for corrective actions
D.Archiving all incident artifacts and closing the case file in the ticketing system
AnswerC

A post-incident review delivers value only when findings translate into tracked remediation. Capturing lessons learned and converting them into corrective actions with named owners and deadlines closes the loop, ensures accountability, and drives measurable improvement in the incident response plan, controls, and monitoring. Without ownership and deadlines, observations remain recommendations that are rarely implemented.

Why this answer

The purpose of a post-incident review is continuous improvement, which requires converting observations into tracked corrective actions with accountable owners and deadlines. Distributing technical details, calculating cost, or archiving artifacts may support governance or records management, but none of them ensures the identified weaknesses are actually fixed, so they do not deliver the lasting improvement the manager seeks.

Exam trap

The trap here is treating the post-incident review as a documentation or reporting exercise, when its essential output is owned, deadline-driven corrective action.

184
MCQmedium

A security manager is drafting the incident response plan and needs to define how the organization will classify and escalate incidents. Executive leadership wants assurance that high-impact incidents reach the right decision-makers quickly. Which of the following should the security manager do FIRST to establish effective incident classification and escalation?

A.Purchase a security information and event management (SIEM) platform with automated alert correlation and threat intelligence feeds.
B.Ask each business unit to independently define its own incident severity scale and reporting thresholds.
C.Instruct the incident response team to notify the board of directors for every confirmed security event regardless of impact.
D.Define severity levels based on business impact criteria and map each level to a defined escalation path and notification timeframe.
AnswerD

Classification must be anchored to business impact so that severity reflects real consequences rather than technical symptoms alone. Mapping each severity level to a specific escalation path and timeframe ensures executives are engaged consistently and quickly for high-impact events. This creates a repeatable, auditable decision structure that satisfies leadership's need for timely notification and gives responders clear triage guidance.

Why this answer

Effective incident classification starts with business impact criteria, because severity must reflect consequences to the organization rather than technical indicators alone. Once severity levels are defined, each must be tied to a specific escalation path and notification timeframe so that executives are engaged promptly for high-impact events. This governance-first approach creates a consistent, repeatable basis for triage and escalation before any tooling or operational detail is layered on top.

Exam trap

The trap here is assuming that acquiring detection tooling or notifying executives broadly constitutes incident classification and escalation, when the foundational step is defining business-impact-based severity levels and their mapped escalation paths.

185
MCQhard

During a data breach investigation, legal counsel instructs the forensics team to preserve evidence under attorney-client privilege. Which of the following actions is most critical to maintain that privilege?

A.Use a separate, isolated network for forensic analysis
B.Limit distribution of forensic reports to individuals with a need-to-know and under legal direction
C.Encrypt all forensic images with a strong algorithm
D.Destroy all preliminary notes after the final report is issued
AnswerB

Attorney-client privilege depends on confidentiality; disclosure to third parties can waive it. Restricting forensic reports to need-to-know recipients acting under legal direction preserves the protected communication channel, satisfying counsel's instruction and preventing inadvertent waiver during the breach investigation.

Why this answer

To maintain attorney-client privilege during a data breach investigation, it is critical to limit distribution of forensic reports to individuals with a need-to-know and under legal direction. This preserves confidentiality, which is essential for privilege to apply. Uncontrolled distribution can waive privilege, exposing sensitive information to discovery.

Exam trap

CISM often tests the misconception that technical security measures like encryption or network isolation are sufficient to maintain attorney-client privilege, but the key is controlling the distribution of information.

How to eliminate wrong answers

Option A is wrong because using a separate network for forensic analysis is a good practice for isolation but does not directly maintain attorney-client privilege; privilege is about confidentiality of communications, not network segmentation. Option C is wrong because encrypting forensic images protects data at rest but does not address the confidentiality of the reports and communications needed for privilege. Option D is wrong because destroying preliminary notes after the final report is issued could be considered spoliation of evidence and is unethical; it does not maintain privilege and may lead to legal sanctions.

186
Multi-Selecthard

An organization is building its incident response capability and wants to ensure it can effectively detect and respond to incidents. Which TWO of the following are the MOST important foundational elements to establish before an incident occurs? (Choose two.)

Select 2 answers
A.Defined incident classification and severity criteria to prioritize response efforts.
B.A documented incident response plan with defined roles and communication procedures.
C.A complete inventory of every software license purchased by the organization.
D.A policy prohibiting any use of encryption within the organization.
E.A list of all employees' personal social media accounts for monitoring.
AnswersA, B

Classification and severity criteria allow the organization to triage incidents consistently, allocate resources appropriately, and determine when to escalate to management or activate the crisis management team. CISM treats this as foundational because it ensures that response efforts are proportional to business impact and that critical incidents receive immediate attention, while lower-severity events are handled efficiently.

Why this answer

The foundational elements for incident response include a documented plan with roles and communication procedures, and defined classification and severity criteria. These enable consistent, prioritized, and coordinated response. Personal social media monitoring, software license inventories, and encryption bans do not provide the structure or detection capability needed before an incident occurs.

Exam trap

The trap here is selecting tangential monitoring or inventory items that sound useful but do not establish the structured response capability CISM requires.

187
Multi-Selecthard

An organization has just contained a malware outbreak on several servers. The incident response manager must decide which activities belong in the eradication phase before restoration begins. Which TWO of the following activities are part of eradication? (Choose two.)

Select 2 answers
A.Removing the malicious binaries and persistence mechanisms from all affected hosts.
B.Isolating the affected network segment to prevent the malware from spreading further.
C.Restoring affected servers from known-good backups and reconnecting them to production.
D.Identifying the vulnerability or misconfiguration that allowed the initial compromise.
E.Patching the exploited software and resetting credentials that may have been exposed on compromised hosts.
AnswersA, E

Eradication is the phase that eliminates the adversary's presence and the vulnerability that allowed it. Deleting malware, scheduled tasks, rogue services, and web shells from every affected host is core eradication work. If any artifact survives on even one system, restoration will reintroduce the compromise, so completeness across the entire affected scope is the defining requirement of this activity.

Why this answer

Eradication removes the adversary's artifacts and the conditions that enabled the compromise. Deleting malicious code and persistence satisfies the first, while patching the exploited flaw and resetting exposed credentials satisfies the second. Containment, root-cause identification, and restoration are separate phases, and completing eradication fully before restoration is what prevents the same incident from recurring.

Exam trap

The trap here is conflating the containment and restoration phases with eradication, so that isolating systems or rebuilding servers is mistaken for removing the threat.

188
Multi-Selectmedium

Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)

Select 2 answers
A.The incident could cause severe reputational damage
B.The incident involves a new type of malware not seen before
C.The incident originated from a third-party supplier
D.The incident has potential for major financial loss or regulatory penalties
E.The incident requires coordination with multiple external vendors
AnswersA, D

Severe reputational damage meets the CMT escalation threshold because it threatens enterprise-wide viability, not just operational continuity. Crisis management governs strategic and stakeholder response, so incidents with potential brand, regulatory or public-trust consequences require their oversight rather than routine incident handling.

Why this answer

Option A is correct because an incident with the potential to cause severe reputational damage meets the threshold for CMT escalation, since crisis management is invoked when business reputation and stakeholder trust are at stake, not merely for technical containment. Option D is correct because potential for major financial loss or regulatory penalties is a classic CMT escalation trigger, as such consequences require executive-level decision-making, legal counsel, and communications coordination beyond the incident response team's scope. Options B, C, and E are not appropriate standalone criteria: novel malware, third-party origin, and multi-vendor coordination are operational or technical factors that the incident response team can typically handle through normal procedures, and they do not by themselves imply the enterprise-wide business impact that defines a crisis warranting CMT involvement.

189
Multi-Selectmedium

An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)

Select 2 answers
A.A template for incident notifications
B.Evidence handling procedures
C.Contact information for law enforcement
D.A list of acceptable forensic tools
E.Chain of custody forms
AnswersB, E

Evidence handling procedures define the chain-of-custody steps, packaging methods and documentation required to preserve artefacts during incident response. This directly satisfies the stem's evidence-handling requirement, ensuring collected data remains admissible and unaltered from seizure through analysis, which generic response or communication components cannot guarantee.

Why this answer

Evidence handling procedures (B) are essential because they define the step-by-step methods for identifying, collecting, preserving, and documenting digital evidence so it remains admissible and unaltered, covering actions like write-blocking drives and hashing files. Chain of custody forms (E) are equally required because they create the documented, unbroken record of who handled each piece of evidence, when, and for what purpose, which is critical for proving integrity in legal or disciplinary proceedings. Together, B and E directly address the core of evidence handling in an incident response plan.

The other options, while useful in a broader IR plan, do not specifically ensure evidence handling: A (incident notification template) supports communication, C (law enforcement contacts) supports escalation, and D (list of acceptable forensic tools) supports tooling choices but does not itself govern evidence integrity or custody.

190
Multi-Selecthard

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

Select 3 answers
A.General Counsel (GC)
B.Chief Information Security Officer (CISO)
C.Security analyst
D.Chief Executive Officer (CEO)
E.Forensic investigator
AnswersA, B, D

The General Counsel advises on legal exposure, regulatory notification duties, contractual obligations, privilege and potential litigation arising from the breach. Including the GC ensures crisis decisions account for legal risk, satisfying the CMT's need for authoritative legal counsel during a major incident.

Why this answer

The General Counsel (GC) is a correct CMT member because major cybersecurity incidents carry legal, regulatory, contractual, and disclosure obligations, so the GC advises on breach notification laws, litigation risk, and privilege. The Chief Information Security Officer (CISO) is correct because the CISO owns the security program and provides executive-level technical and strategic leadership for incident response decisions. The Chief Executive Officer (CEO) is correct because a major incident can threaten the entire organization, and the CEO holds ultimate authority for business continuity, stakeholder communication, and resource commitment.

A security analyst and a forensic investigator are not appropriate CMT members; they are operational/technical responders who perform hands-on triage and evidence analysis and report to the CMT rather than sitting on it.

Exam trap

The trap here is confusing operational roles (Security Analyst, Forensic Investigator) with strategic, decision-making CMT members, leading candidates to select technical responders who execute tasks rather than executives who govern the incident response.

← PreviousPage 3 of 3 · 190 questions total

Ready to test yourself?

Try a timed practice session using only Incident Management questions.