CISM Incident Management Practice Question
Which THREE of the following are objectives of a lessons learned meeting after an incident? (Select three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine what worked well and what did not
Option A is correct because a lessons learned (post-incident) meeting evaluates the incident response to determine what worked well and what did not, so successful practices can be reinforced and gaps addressed. Option D is correct because the meeting's output includes recommendations for improvement, such as updating procedures, controls, or training to prevent recurrence or improve future response. Option E is correct because identifying what happened during the incident — reconstructing the timeline, root cause, and scope — is a core objective that grounds the analysis and subsequent recommendations. Option B is not an objective; lessons learned meetings are blameless and focus on process improvement rather than assigning fault. Option C is not an objective of the meeting itself; sharing indicators of compromise with an ISAC is a separate threat-intelligence activity that may occur, but it is not a stated goal of the lessons learned session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Determine what worked well and what did not
Why this is correct
Reviewing what worked and what failed directly satisfies the stem's requirement to identify improvement areas, feeding corrective actions back into the incident response plan. This retrospective analysis exposes control gaps and successful practices, enabling Microsoft Entra ID and other security measures to be tuned against future threats.
- ✗
Assign blame for the incident
Why it's wrong here
Lessons learned meetings examine root cause and improve controls; assigning blame suppresses the honest reporting the review depends on. It is tempting because accountability feels like a natural post-incident outcome, and in a disciplinary or HR investigation identifying a responsible individual would be the correct objective.
- ✗
Share indicators of compromise with an ISAC
Why it's wrong here
Sharing indicators of compromise with an ISAC is threat-intelligence dissemination, not an internal lessons learned objective, which focuses on control gaps and process improvements. It is tempting because post-incident reviews often surface IOCs, and in a threat-intelligence sharing process distributing them to an ISAC would be correct.
- ✓
Develop recommendations for improvement
Why this is correct
Developing recommendations for improvement is a core objective of the lessons learned meeting, satisfying the stem's requirement to identify post-incident objectives. The meeting analyses root cause and control gaps, then produces actionable remediation to strengthen the incident response plan and prevent recurrence.
- ✓
Identify what happened during the incident
Why this is correct
Reconstructing the incident timeline establishes the factual sequence of events, satisfying the objective of understanding what occurred. This shared record lets participants examine detection, escalation and response gaps, forming the evidence base from which later improvements and control changes are derived.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.