CISM Incident Management Practice Question
Which of the following is the BEST approach for sharing threat intelligence indicators of compromise (IoCs) after an incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Share IoCs with industry peers via the relevant ISAC.
Sharing IoCs with an ISAC (Information Sharing and Analysis Center) helps the broader community defend against similar attacks, which is a key post-incident activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report IoCs to law enforcement only.
Why it's wrong here
Reporting IoCs solely to law enforcement delays dissemination to peer organisations that could block the same indicators, and law enforcement channels typically handle prosecution rather than real-time machine-readable sharing. It is tempting because reporting to authorities satisfies regulatory and legal obligations after a breach, and would be the right choice when the incident requires criminal investigation or mandatory statutory notification.
- ✓
Share IoCs with industry peers via the relevant ISAC.
Why this is correct
An ISAC provides a trusted, sector-specific sharing channel with anonymisation and legal protections, letting peers block the same indicators quickly. This satisfies the stem's need for the best sharing approach, since public disclosure risks tipping off the attacker and exposing the victim.
- ✗
Keep IoCs confidential to protect the organization's reputation.
Why it's wrong here
Keeping IoCs confidential prevents other organisations from blocking the same adversary infrastructure, so containment stays local and the attacker reuses it freely. Confidentiality suits internal forensic evidence or legally privileged material, where disclosure could prejudice an investigation. Sharing is the point of threat intelligence: IoCs lose value unless circulated to those who can act on them.
- ✗
Publish IoCs on the organization's public website.
Why it's wrong here
Publishing IoCs on a public website exposes sensitive detection data to adversaries, who can alter infrastructure to evade the very indicators being shared. It is tempting because public disclosure suits transparency reporting or regulatory breach notification, where informing customers and the public is the actual objective rather than enabling peer defences.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.