CISM Incident Management Practice Question
Which THREE of the following are key activities during the post-incident phase of incident management? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Updating incident response plans and playbooks based on lessons learned
Option A is correct because the post-incident phase includes reviewing what happened and feeding lessons learned back into the incident response plan and playbooks so future responses improve. Option C is correct because root cause analysis, often using techniques such as 5 Whys or fishbone diagrams, is a core post-incident activity that identifies the underlying cause rather than just the symptom. Option D is correct because sharing indicators of compromise with relevant Information Sharing and Analysis Centers (ISACs) is a post-incident coordination activity that helps the broader community detect and defend against the same threat. Option B is not correct because activating the disaster recovery site is a response or recovery action, not a post-incident review activity. Option E is not correct because implementing immediate containment measures occurs during the containment phase of incident response, before the post-incident phase begins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Updating incident response plans and playbooks based on lessons learned
Why this is correct
Feeding lessons learned back into plans and playbooks closes the improvement loop, ensuring the next incident is handled better. This directly satisfies the post-incident phase's objective of institutionalising corrective actions rather than merely restoring service.
- ✗
Activating the disaster recovery site
Why it's wrong here
Activating the disaster recovery site is a response and recovery action, executed while the incident is active, not after closure. It is tempting because DR invocation follows major incidents, and it would be correct during the recovery phase when primary operations must resume at an alternate site.
- ✓
Conducting root cause analysis using techniques like 5 Whys
Why this is correct
Root cause analysis using techniques like 5 Whys satisfies the post-incident requirement to identify underlying causes rather than symptoms, preventing recurrence. It examines why controls failed, feeding corrective actions into the lessons-learned process and closing the incident management lifecycle.
- ✓
Sharing indicators of compromise with relevant ISACs
Why this is correct
Publishing indicators of compromise to relevant ISACs lets peer organisations detect the same threat, extending defensive value beyond the victim. This sharing is a recognised post-incident activity, distinct from containment or eradication work performed earlier.
- ✗
Implementing immediate containment measures
Why it's wrong here
Immediate containment measures occur during the response phase, restricting spread while the incident is live; post-incident work reviews lessons and closes records. It is tempting because containment is critical to incident handling, and it would be correct as an early response activity once an incident is declared.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.