Courseiva
hardMultiple SelectObjective-mapped

CISM Practice Question: Which THREE are key components of an effective…

Which THREE are key components of an effective post-incident review?

⚠ Common exam trap

Candidates often confuse post-incident review outcomes (like budget increases) with the core review components, or mistakenly think assigning blame is part of a proper review, when CISM emphasizes a no-blame culture focused on process improvement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document lessons learned

Documenting lessons learned captures actionable insights from the incident, enabling the organization to improve future detection, response, and prevention. This aligns with the CISM Incident Management domain, where post-incident reviews focus on process improvement rather than punitive measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Document lessons learned

    Why this is correct

    Correct: Capturing what worked and what didn't drives future improvements.

  • Increase security budget

    Why it's wrong here

    Budget increase may be a recommendation but is not a component of the review itself.

  • Assign blame

    Why it's wrong here

    Blame assignment destroys trust and hinders improvement.

  • Update incident response plan

    Why this is correct

    Correct: The plan should be revised based on findings.

  • Determine root cause

    Why this is correct

    Correct: Understanding why the incident occurred is fundamental.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are recommended practices when conducting a post-incident review? (Select TWO)

hard
  • A.Document lessons learned and improvement actions
  • B.Update the incident response plan immediately
  • C.Assign blame to responsible individuals
  • D.Identify the root cause of the incident
  • E.Reimage all affected systems

Why A: Documenting lessons learned and improvement actions is a core output of a post-incident review, enabling the organization to refine security controls, processes, and training. This practice aligns with the continuous improvement cycle in incident management, ensuring that each incident contributes to stronger defenses. Without this documentation, the same vulnerabilities or procedural gaps may be exploited repeatedly.

Variation 2. An organization's incident response team is conducting a lessons learned meeting after a major incident. Which outcome is MOST critical to document?

medium
  • A.Root cause analysis
  • B.Detailed timeline of events
  • C.List of tools used
  • D.Total cost of the incident

Why A: The root cause analysis is the most critical outcome to document because it identifies the underlying technical failure that allowed the incident to occur, enabling the organization to implement permanent corrective actions. Without a documented root cause, the incident response process cannot transition from containment to prevention, and the organization risks repeating the same failure. In CISM's Incident Management domain, the lessons learned phase specifically aims to improve future response capability by addressing systemic weaknesses, which requires a clear understanding of why the incident happened.

Variation 3. During an incident, the incident response team determines that a compromised account was used to exfiltrate data. The account has been disabled. What is the NEXT best action to prevent similar incidents?

medium
  • A.Notify potentially affected customers
  • B.Perform a root cause analysis
  • C.Reset passwords for all user accounts
  • D.Review authentication logs for other anomalies

Why B: Performing a root cause analysis (RCA) is the next best action because it systematically identifies the underlying vulnerability or control weakness that allowed the account compromise. Without understanding how the attacker gained access—whether through phishing, credential stuffing, or a software vulnerability—simply disabling the account does not prevent recurrence. The RCA will inform targeted remediation, such as patching, policy changes, or implementing multi-factor authentication (MFA).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.