Courseiva
Incident Management →hardMultiple Select

CISM Incident Management Practice Question

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

⚠ Common exam trap

It's easy for candidates to confuse operational roles (Security Analyst, Forensic Investigator) with strategic, decision-making CMT members, leading candidates to select technical responders who execute tasks rather than executives who govern the incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

General Counsel (GC)

The General Counsel (GC) is a correct CMT member because major cybersecurity incidents carry legal, regulatory, contractual, and disclosure obligations, so the GC advises on breach notification laws, litigation risk, and privilege. The Chief Information Security Officer (CISO) is correct because the CISO owns the security program and provides executive-level technical and strategic leadership for incident response decisions. The Chief Executive Officer (CEO) is correct because a major incident can threaten the entire organization, and the CEO holds ultimate authority for business continuity, stakeholder communication, and resource commitment. A security analyst and a forensic investigator are not appropriate CMT members; they are operational/technical responders who perform hands-on triage and evidence analysis and report to the CMT rather than sitting on it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    General Counsel (GC)

    Why this is correct

    The General Counsel advises on legal exposure, regulatory notification duties, contractual obligations, privilege and potential litigation arising from the breach. Including the GC ensures crisis decisions account for legal risk, satisfying the CMT's need for authoritative legal counsel during a major incident.

  • ✓

    Chief Information Security Officer (CISO)

    Why this is correct

    The CISO provides authoritative technical assessment of the incident's scope, containment status and residual risk, and directs security response efforts. This expertise lets the crisis management team make informed business decisions, satisfying the CMT's requirement for senior security leadership.

  • ✗

    Security analyst

    Why it's wrong here

    A security analyst performs monitoring, triage and investigation, reporting findings upward rather than directing enterprise-wide response, communications and business continuity decisions during a major incident. The role is tempting because analysts hold the technical detail, and would be appropriate on the tactical incident response team rather than the strategic crisis management team.

  • ✓

    Chief Executive Officer (CEO)

    Why this is correct

    The CEO provides executive authority to make strategic, cross-functional decisions during a major cybersecurity incident, including business continuity, regulatory disclosure and resource commitment. This satisfies the stem's requirement for appropriate crisis management team membership at the highest organisational level.

  • ✗

    Forensic investigator

    Why it's wrong here

    A forensic investigator gathers and preserves evidence for legal or disciplinary purposes, an investigative function rather than the executive decision-making, communications and continuity authority a crisis management team requires. It is tempting because forensics is central to major incidents, and would be correct within the investigation workstream supporting the CMT.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.