Courseiva
Incident Management →hardMultiple Select

CISM Incident Management Practice Question

Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Updating incident response plans and playbooks based on lessons learned

Option A is correct because the post-incident phase includes reviewing what happened and feeding lessons learned back into the incident response plan and playbooks so future responses improve. Option C is correct because root cause analysis, often using techniques such as 5 Whys or fishbone diagrams, is a core post-incident activity that identifies the underlying cause rather than just the symptom. Option D is correct because sharing indicators of compromise with relevant Information Sharing and Analysis Centers (ISACs) is a post-incident coordination activity that helps the broader community detect and defend against the same threat. Option B is not correct because activating the disaster recovery site is a response or recovery action, not a post-incident review activity. Option E is not correct because implementing immediate containment measures occurs during the containment phase of incident response, before the post-incident phase begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Updating incident response plans and playbooks based on lessons learned

    Why this is correct

    Feeding lessons learned back into plans and playbooks closes the improvement loop, ensuring the next incident is handled better. This directly satisfies the post-incident phase's objective of institutionalising corrective actions rather than merely restoring service.

  • ✗

    Activating the disaster recovery site

    Why it's wrong here

    Activating the disaster recovery site is a response and recovery action, executed while the incident is active, not after closure. It is tempting because DR invocation follows major incidents, and it would be correct during the recovery phase when primary operations must resume at an alternate site.

  • ✓

    Conducting root cause analysis using techniques like 5 Whys

    Why this is correct

    Root cause analysis using techniques like 5 Whys satisfies the post-incident requirement to identify underlying causes rather than symptoms, preventing recurrence. It examines why controls failed, feeding corrective actions into the lessons-learned process and closing the incident management lifecycle.

  • ✓

    Sharing indicators of compromise with relevant ISACs

    Why this is correct

    Publishing indicators of compromise to relevant ISACs lets peer organisations detect the same threat, extending defensive value beyond the victim. This sharing is a recognised post-incident activity, distinct from containment or eradication work performed earlier.

  • ✗

    Implementing immediate containment measures

    Why it's wrong here

    Immediate containment measures occur during the response phase, restricting spread while the incident is live; post-incident work reviews lessons and closes records. It is tempting because containment is critical to incident handling, and it would be correct as an early response activity once an incident is declared.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.