Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

Which of the following is an example of an external stakeholder that should be included in the incident response plan's vendor contacts list?

⚠ Common exam trap

CISM often tests the distinction between internal roles and external stakeholders, and candidates may incorrectly assume that high-level executives like the CISO or board are external because they have oversight responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External legal counsel

External legal counsel is an external stakeholder because they are not employees of the organization but are engaged to provide specialized legal advice during incidents. In an incident response plan, vendor contacts must include external parties such as legal counsel, forensic firms, and PR agencies who can be called upon when needed. The CISO, incident response manager, and board of directors are all internal roles and would not be listed as vendor contacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Chief Information Security Officer

    Why it's wrong here

    The CISO is an internal role within the organisation, so belongs in internal escalation contacts rather than the external vendor list. Including senior security leadership is tempting because they oversee incident response, but external contacts cover third parties such as cloud providers, ISPs, legal counsel and regulators.

  • ✗

    Incident response manager

    Why it's wrong here

    The incident response manager is an internal role within the organisation, so belongs in the internal escalation contacts rather than the vendor list. It is tempting because the title sounds incident-focused, and it would be correct if the question asked for internal response team members.

  • ✓

    External legal counsel

    Why this is correct

    External legal counsel sits outside the organisation yet is engaged during incidents for breach notification, regulatory and privilege advice. Listing them as a vendor contact satisfies the stem's requirement for an external stakeholder, since internal roles such as the CISO or IT staff are not external parties.

  • ✗

    Board of directors

    Why it's wrong here

    The board of directors is an internal governance body, not an external vendor, so it does not belong on the vendor contacts list. It is tempting because boards receive incident briefings, and it would be correct if the question asked for internal executive stakeholders.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.