CISM Incident Management Practice Question
Following containment of a ransomware incident, the incident response team is conducting a root cause analysis. Which method involves repeatedly asking 'why' to drill down to underlying causes?
⚠ Common exam trap
CISM often tests the confusion between root cause analysis tools — candidates may pick Fishbone diagram because it also analyzes causes, but only 5 Whys specifically uses the iterative 'why' questioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
5 Whys
The 5 Whys technique involves repeatedly asking 'why' to drill down from a symptom to its root cause. It was developed by Sakichi Toyoda and is widely used in incident response and quality management. By asking 'why' five times, teams can uncover underlying process failures rather than stopping at superficial causes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pareto analysis
Why it's wrong here
Pareto analysis ranks causes by frequency or impact using the 80/20 principle, directing effort to the largest contributors. It cannot drill through causal chains to an underlying root, which requires iterative 'why' questioning. Pareto would be chosen when prioritising which of many identified problems to address first.
- ✗
SWOT analysis
Why it's wrong here
SWOT analysis assesses internal strengths and weaknesses against external opportunities and threats, supporting strategic planning rather than incident investigation. It produces no causal chain and asks no iterative 'why' questions. It would be the right tool when evaluating an organisation's security posture or a proposed control's strategic fit.
- ✓
5 Whys
Why this is correct
5 Whys is an iterative interrogative technique that repeatedly asks 'why' to strip away symptomatic layers and expose the underlying causal factor. Applied after containment, it drills from the immediate ransomware trigger down to the root weakness, satisfying the root cause analysis requirement.
- ✗
Fishbone diagram
Why it's wrong here
A fishbone diagram sorts contributing causes into categories such as people, process and technology, but does not iterate questioning to reach a root cause. It suits broad brainstorming across many suspected factors; the repeated 'why' interrogation described in the stem is the Five Whys technique.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.