Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

During a P1 incident involving a ransomware attack, the incident response manager needs to communicate with executives. Which of the following is the most appropriate approach for executive communication?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send hourly situation reports (sitreps) focusing on business impact and key actions

For critical incidents, hourly sitreps (situation reports) are recommended to keep executives informed. Avoiding speculation and preserving legal privilege with counsel involvement are also key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include speculative root causes to show thoroughness

    Why it's wrong here

    Speculative root causes during an active P1 risk misleading executives and premature conclusions; communications should state confirmed facts and impact. Root-cause hypotheses belong in the technical investigation, not executive updates, and are only appropriate once evidence supports them, typically during post-incident review.

  • ✗

    Wait until the incident is fully resolved before communicating

    Why it's wrong here

    Withholding updates until full resolution leaves executives unable to make business continuity, legal or disclosure decisions while the ransomware is still spreading. Regular interim communication is required. Waiting for closure suits routine low-severity tickets, not a P1 where executive action is needed immediately.

  • ✓

    Send hourly situation reports (sitreps) focusing on business impact and key actions

    Why this is correct

    Hourly sitreps satisfy the P1 escalation cadence executives require during ransomware, prioritising business impact and key actions over technical forensics. This keeps decision-makers informed on service disruption, containment progress and recovery timelines without overwhelming them with indicators of compromise, preserving their ability to authorise business-continuity and communication decisions.

  • ✗

    Provide detailed technical analysis in every update

    Why it's wrong here

    Executives need business impact, containment status and decisions, not packet captures or forensic detail, which obscures the message and delays action. Detailed technical analysis suits the incident response team's own working notes or a technical bridge call, not executive-level communication during a P1.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.