Courseiva
Incident Management →hardMultiple Select

CISM Incident Management Practice Question

Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine what worked well and what did not

Option A is correct because a lessons learned (post-incident) meeting evaluates the incident response to determine what worked well and what did not, so successful practices can be reinforced and gaps addressed. Option D is correct because the meeting's output includes recommendations for improvement, such as updating procedures, controls, or training to prevent recurrence or improve future response. Option E is correct because identifying what happened during the incident — reconstructing the timeline, root cause, and scope — is a core objective that grounds the analysis and subsequent recommendations. Option B is not an objective; lessons learned meetings are blameless and focus on process improvement rather than assigning fault. Option C is not an objective of the meeting itself; sharing indicators of compromise with an ISAC is a separate threat-intelligence activity that may occur, but it is not a stated goal of the lessons learned session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Determine what worked well and what did not

    Why this is correct

    Reviewing what worked and what failed directly satisfies the stem's requirement to identify improvement areas, feeding corrective actions back into the incident response plan. This retrospective analysis exposes control gaps and successful practices, enabling Microsoft Entra ID and other security measures to be tuned against future threats.

  • ✗

    Assign blame for the incident

    Why it's wrong here

    Lessons learned meetings examine root cause and improve controls; assigning blame suppresses the honest reporting the review depends on. It is tempting because accountability feels like a natural post-incident outcome, and in a disciplinary or HR investigation identifying a responsible individual would be the correct objective.

  • ✗

    Share indicators of compromise with an ISAC

    Why it's wrong here

    Sharing indicators of compromise with an ISAC is threat-intelligence dissemination, not an internal lessons learned objective, which focuses on control gaps and process improvements. It is tempting because post-incident reviews often surface IOCs, and in a threat-intelligence sharing process distributing them to an ISAC would be correct.

  • ✓

    Develop recommendations for improvement

    Why this is correct

    Developing recommendations for improvement is a core objective of the lessons learned meeting, satisfying the stem's requirement to identify post-incident objectives. The meeting analyses root cause and control gaps, then produces actionable remediation to strengthen the incident response plan and prevent recurrence.

  • ✓

    Identify what happened during the incident

    Why this is correct

    Reconstructing the incident timeline establishes the factual sequence of events, satisfying the objective of understanding what occurred. This shared record lets participants examine detection, escalation and response gaps, forming the evidence base from which later improvements and control changes are derived.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.