Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

Which of the following is the PRIMARY reason for including communication templates in the incident response plan?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure consistent and timely messaging to stakeholders.

Communication templates ensure that notifications are consistent, accurate, and timely during the stress of an incident, reducing the risk of errors or omissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To reduce the workload on the communications lead.

    Why it's wrong here

    Templates exist to ensure consistent, timely, pre-approved messaging during high-pressure incidents, not to reduce one person's workload. It tempts because templates do save drafting effort, but workload reduction is a by-product; the primary driver is speed and accuracy of stakeholder communication.

  • ✗

    To comply with regulatory requirements for breach notification.

    Why it's wrong here

    Regulatory notification is governed by legal and privacy processes with jurisdiction-specific timing and content rules; templates support but do not satisfy compliance. It tempts because breach notification is mandatory, yet the primary purpose is consistent, rapid communication, not regulatory adherence itself.

  • ✓

    To ensure consistent and timely messaging to stakeholders.

    Why this is correct

    Pre-approved templates remove drafting delays and standardise wording, so stakeholders receive accurate, timely notifications during high-pressure incidents. This directly satisfies the stem's primary-reason constraint: communication speed and consistency, rather than investigation, containment or forensic accuracy, which other options address.

  • ✗

    To avoid legal liability by using approved language.

    Why it's wrong here

    Templates standardise message content and approval flow, not legal protection; approved wording cannot pre-empt liability arising from disclosure failures. It tempts because legal review of breach communications is genuinely required, but that is a notification-content control, not the primary purpose of pre-built templates.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.