CISM Incident Management Practice Question
Which THREE of the following are typical roles in an incident response team? (Select THREE)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IR manager
The IR manager (A) is a core role that coordinates the entire incident response effort, making decisions on escalation, communication, and resource allocation during an incident. Forensic investigators (C) are essential for collecting, preserving, and analyzing evidence such as disk images, memory dumps, and logs to determine the scope and root cause of a breach. Security analysts (D) form the frontline technical role, monitoring SIEM alerts, triaging events, and performing initial containment and eradication actions. Human resources (B) and internal audit (E) may be consulted for employee-related or compliance matters, but they are supporting stakeholders rather than typical standing roles within the incident response team itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IR manager
Why this is correct
The IR manager owns and directs the response, coordinating the team, making escalation decisions and liaising with executives and the crisis management team. This command-and-control function is a standard, defined role in any incident response structure.
- ✗
Human resources representative
Why it's wrong here
Human resources handles personnel matters such as disciplinary or employment consequences, not the technical containment, eradication and recovery activities an incident response team performs. It is tempting because HR is consulted when insider incidents or staff communications arise, and it would be the right participant when an incident triggers employee relations or legal-employment action.
- ✓
Forensic investigators
Why this is correct
Forensic investigators perform evidence acquisition and analysis — disk, memory, network and log examination — to establish scope, root cause and attribution while preserving admissibility. This technical investigative capability is a distinct, typical IR team role, separate from management and monitoring functions.
- ✓
Security analysts
Why this is correct
Security analysts monitor alerts, triage detections and perform initial investigation and containment within the SOC. Their continuous detection and first-response duties make them a standard IR team role, feeding validated incidents to the IR manager and forensic investigators.
- ✗
Internal audit representative
Why it's wrong here
Internal audit provides independent assurance after the fact; it does not perform the detection, containment or eradication duties of an incident response team. It is tempting because audit reviews incident handling and evidence, and it would be the correct function when assessing whether response processes and controls operated effectively post-incident.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.