Courseiva

CISM · topic practice

Incident Management practice questions

CISM Domain 3 (Incident Management) covers preparing for, detecting, responding to, and recovering from security incidents while preserving evidence and coordinating business continuity. Questions test judgment on incident classification, escalation to crisis management, forensic evidence handling, root cause analysis, and post-incident review. Expect scenario-based items asking you to select the BEST or FIRST action, often distinguishing technical response from management and governance responsibilities.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Incident Management

What the exam tests

What to know about Incident Management

You must be able to apply the incident response lifecycle to scenarios, prioritize actions, assign crisis team responsibilities, and protect evidence. The single most important thing: identify whether the question tests technical response or management escalation, then choose the action that fits that layer and preserves business and legal interests.

Incident response plan phases: preparation, detection, containment, eradication, recovery, and lessons learned

Evidence handling: chain of custody, forensic imaging, order of volatility, and legal hold procedures

Crisis management team roles, including CEO accountability for business decisions and stakeholder communication

Threat intelligence sharing via trusted frameworks such as ISACs and STIX/TAXII indicators

Watch out for

Common Incident Management exam traps

  • ▸Choosing technical containment steps when the question asks for the FIRST management or governance action, such as activating the crisis team or notifying executives.
  • ▸Confusing the CEO's crisis role with the CISO's operational role; the CEO decides business impact and communication, not forensic or technical remediation.
  • ▸Overlooking evidence preservation requirements, such as capturing volatile data before powering off systems or failing to maintain chain of custody documentation.

Practice set

Incident Management questions

20 questions · select your answer, then reveal the explanation

During a P1 (critical) incident, the incident response manager has been providing hourly situation reports (sitreps) to executives. What is the primary reason for involving legal counsel in these communications?

After a supply chain attack, the incident response team identifies that a third-party vendor's compromised credentials were used to access the organization's network. Which incident category should this be classified under?

During a major security incident classified as P1, which of the following is the MOST appropriate communication frequency to the executive team?

Which of the following is the PRIMARY purpose of an incident response plan?

During a DDoS attack classified as P2, what is the EXPECTED response time and notification level?

When should an incident response transition to business continuity and disaster recovery (BC/DR) activation?

Which of the following is the FIRST step when engaging an external forensics firm for an incident?

Which TWO of the following are key roles on the crisis management team (CMT) for a major cybersecurity incident? (Select two.)

Which THREE of the following are incident severity levels defined in a typical incident management program? (Select three.)

An organization's incident response team is handling a P2 incident involving an insider threat. The team has identified the employee responsible. The communications lead is preparing a notification to affected parties. Which of the following should be included in the notification?

Which incident severity level requires executive notification and a 24/7 response?

During a DDoS attack, the incident response team is struggling to mitigate the attack. The team decides to engage the organization's ISP and a DDoS mitigation service. Which of the following should be done FIRST?

Following a credential compromise incident, the incident response team is conducting root cause analysis using the 5 Whys technique. The first 'why' reveals that the password was weak. The second 'why' reveals that the password policy allowed simple passwords. What should be the focus of the third 'why'?

During a P1 incident, the incident response manager is preparing an executive sitrep. Which of the following should be included to preserve legal privilege?

An incident has been declared as P2 (high severity). According to the incident classification, what is the expected response timeframe and notification requirement?

An organization maintains evidence handling procedures for incident response. A forensic investigator needs to collect a hard drive from a compromised server. Which of the following is the MOST critical step to ensure admissibility in court?

An organization's incident response team is handling a P2 insider threat incident involving unauthorized access to customer data. According to the incident classification, which of the following is the MOST appropriate notification and response timeframe?

During a P1 incident, the crisis management team (CMT) has been activated. The CEO asks for an hourly sitrep. Which of the following is the MOST appropriate content for the sitrep?

An organization has experienced a DDoS attack that is overwhelming its internet-facing services. The incident response team has implemented mitigations, but services remain degraded. The maximum tolerable downtime (MTD) for the affected services is 4 hours, and 3 hours have passed. Which of the following should the incident manager do NEXT?

An organization is conducting a root cause analysis after a data breach. Which of the following sequences BEST aligns with the 5 Whys approach from a CISM perspective?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Incident Management sessions

Start a Incident Management only practice session

Every question in these sessions is drawn from the Incident Management domain — nothing else.

Related practice questions

Related CISM topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISM exam test about Incident Management?
You must be able to apply the incident response lifecycle to scenarios, prioritize actions, assign crisis team responsibilities, and protect evidence. The single most important thing: identify whether the question tests technical response or management escalation, then choose the action that fits that layer and preserves business and legal interests.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Incident Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Incident Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISM topics?
Use the topic links above to move to related areas, or go back to the CISM question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISM exam covers. They are not copied from any real exam or dump site.