Courseiva
easyMultiple Select

CISM Practice Question: Which THREE of the following are key phases of…

Which THREE of the following are key phases of the incident management lifecycle according to NIST or ISO? (Choose three.)

⚠ Common exam trap

The ISACA CISM exam often tests candidates by including plausible-sounding operational activities (like Encryption or Board reporting) as distractors, leading them to confuse security controls or governance tasks with the formal lifecycle phases defined by NIST and ISO standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detection & Analysis

Option E (Preparation) is correct because both the NIST SP 800-61 incident response lifecycle and ISO/IEC 27035 begin with a preparation phase, covering activities such as establishing an IR policy, forming the CSIRT, acquiring tools, and conducting training before an incident occurs. Option A (Detection & Analysis) is correct because it is the phase where monitoring, event triage, and validation determine whether an event is a genuine incident and establish its scope and impact. Option D (Containment, Eradication & Recovery) is correct because it is the core NIST phase that limits damage, removes the root cause (e.g., malware, compromised accounts), and restores affected systems to normal operation. Option B (Encryption) is not a lifecycle phase but a security control or technology that may be used within various phases. Option C (Board reporting) is not a defined phase in NIST SP 800-61 or ISO/IEC 27035; executive communication is an activity that can occur throughout the lifecycle rather than a distinct phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detection & Analysis

    Why this is correct

    Detection and analysis is a core lifecycle phase in both NIST SP 800-61 and ISO/IEC 27035, covering monitoring, event triage and determining whether an incident has occurred. It precedes containment, eradication and recovery, forming the analytical stage that informs every subsequent response decision.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a protective control applied to data, not a phase of the NIST or ISO incident management lifecycle, which covers preparation, detection and analysis, containment, eradication, recovery, and post-incident activity. It tempts because encryption appears throughout incident response guidance as a safeguard, not as a lifecycle stage.

  • ✗

    Board reporting

    Why it's wrong here

    Board reporting is a governance and oversight activity, not a NIST or ISO incident response lifecycle phase such as preparation, detection and analysis, containment, eradication, recovery, or post-incident activity. It tempts because executive reporting genuinely matters in security programme management, just outside the incident lifecycle itself.

  • ✓

    Containment, Eradication & Recovery

    Why this is correct

    Containment, eradication and recovery form the response phase that limits incident spread, removes the threat and restores services, satisfying the stem's requirement for a NIST/ISO lifecycle phase. NIST SP 800-61 places these within its response stage, distinct from preparation, detection and post-incident activity.

  • ✓

    Preparation

    Why this is correct

    Preparation underpins the entire incident management lifecycle, covering policy, training, tooling and communication readiness before an event occurs. NIST SP 800-61 and ISO/IEC 27035 both identify it as a distinct phase, satisfying the stem's requirement for a recognised lifecycle stage.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.