CISM Incident Management Practice Question
During a P1 (critical) security incident involving a ransomware attack that has encrypted critical servers, which role is primarily responsible for coordinating the overall response and ensuring timely communication to executive leadership?
⚠ Common exam trap
CISM exam often tests the distinction between tactical roles (security analyst, forensic investigator) and the strategic coordination role (incident response manager). Candidates may mistakenly choose the communications lead because they confuse 'communication to executives' with the overall coordination responsibility, but the IRM owns the overall incident command structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response manager
In a P1 ransomware incident, the incident response manager (IRM) is responsible for orchestrating the overall response, prioritizing containment over eradication, and ensuring that executive leadership receives timely, accurate status updates. Unlike technical roles, the IRM owns the incident command structure, coordinates cross-functional teams, and manages communication escalations to stakeholders, which is critical when encrypted servers demand immediate business continuity decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident response manager
Why this is correct
The incident response manager owns end-to-end coordination of the P1 response, directing technical teams while acting as the single conduit for executive updates, which satisfies the stem's requirement for both overall coordination and timely leadership communication.
- ✗
Security analyst
Why it's wrong here
A security analyst performs triage and technical investigation, but lacks the authority to direct response teams or brief executives. The role is tempting because analysts detect and escalate the incident; it would be correct for the hands-on containment and evidence-gathering tasks within the response.
- ✗
Forensic investigator
Why it's wrong here
A forensic investigator preserves and analyses evidence, supporting the response rather than coordinating it or communicating with leadership. The role is tempting because ransomware cases demand forensic scoping; it would be correct for determining initial access vector and data exfiltration scope under the incident manager's direction.
- ✗
Communications lead
Why it's wrong here
The communications lead drafts and distributes messaging, but does not command the technical response or own executive accountability for the incident. The role is tempting because it handles executive updates; it would be correct for managing press statements and stakeholder notifications once the incident manager sets strategy.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.