CISM Incident Management Practice Question
Which component of the incident response programme provides step-by-step technical instructions for handling a specific type of security incident?
⚠ Common exam trap
It's easy for candidates to confuse the incident response plan (strategic, high-level) with the playbook (tactical, incident-specific), often selecting the plan because it sounds like the most comprehensive document, but the question explicitly asks for 'step-by-step technical instructions' which only the playbook provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response playbook
C is correct because an incident response playbook provides detailed, step-by-step technical instructions for handling a specific type of security incident (e.g., ransomware, DDoS, phishing). Unlike the higher-level incident response plan, a playbook contains precise technical actions, such as commands to isolate a host, indicators of compromise (IOCs) to block, and escalation criteria tailored to a particular threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident response plan
Why it's wrong here
The incident response plan is the overarching document defining scope, roles, phases and escalation, not the granular technical steps for one incident type. It is tempting because it governs the whole programme, and would be correct when the question asks for the organisation's overall incident handling framework.
- ✗
Incident response policy
Why it's wrong here
The incident response policy states management's intent, principles and mandatory requirements, leaving technical procedures to supporting playbooks. It is tempting because policy sits at the top of the programme hierarchy, and would be correct when the question asks for the authority establishing the incident response mandate.
- ✓
Incident response playbook
Why this is correct
An incident response playbook delivers the step-by-step technical instructions the stem demands, mapping specific containment, eradication and recovery actions to a defined incident type. Unlike broader plans or procedures, it prescribes exact commands and decision points, so responders execute consistent, repeatable actions under pressure.
- ✗
Communication templates
Why it's wrong here
Communication templates hold pre-drafted notification wording for stakeholders, regulators and media, containing no technical remediation steps. They are tempting because they are part of the response toolkit, and would be correct when the requirement is consistent, pre-approved messaging during an incident.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.