Courseiva
easyMultiple Select

CISM Practice Question: Which THREE steps are essential in the…

Which THREE steps are essential in the post-incident review process?

⚠ Common exam trap

ISACA CISM often tests the distinction between a constructive, process-oriented review and a blame-seeking exercise; the trap here is that candidates may mistakenly think 'assigning blame' is necessary for accountability, when in fact it undermines the entire purpose of the review.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify lessons learned and process improvements

Option A is correct because the post-incident review must capture lessons learned and identify concrete process improvements so the organization does not repeat the same mistakes. Option B is correct because findings from the review should be fed back into the incident response plan, updating playbooks, contact lists, and procedures to reflect what actually worked and what failed. Option D is correct because a root cause analysis is essential to determine the underlying technical or procedural cause of the incident rather than just its symptoms, enabling effective remediation. Option C is not part of the process because post-incident reviews are blameless, focusing on systemic causes rather than punishing individuals, which would discourage honest reporting. Option E is unrelated because renewing vendor contracts is a procurement activity, not a step in reviewing and learning from an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identify lessons learned and process improvements

    Why this is correct

    Capturing lessons learned converts the incident timeline and response actions into documented improvements, closing the feedback loop that distinguishes a post-incident review from mere incident closure. Without this step, the review produces no actionable change to controls, monitoring or response procedures.

  • ✓

    Update the incident response plan

    Why this is correct

    Feeding review findings back into the incident response plan keeps the documented procedures current, so the next response reflects what actually worked and what failed. This satisfies the review's purpose of improving future capability rather than only documenting the past event.

  • ✗

    Assign blame for the incident

    Why it's wrong here

    Post-incident review exists to find root cause and improve controls, so blaming individuals suppresses reporting and hides systemic weaknesses. It is tempting because accountability feels like a natural part of incident handling, and disciplinary follow-up is a separate HR matter, not a review step.

  • ✓

    Conduct a root cause analysis

    Why this is correct

    Root cause analysis determines the underlying weakness, such as an unpatched service or misconfigured control, that allowed the incident. Addressing that cause prevents recurrence, which is the review's central objective; treating only symptoms leaves the same exposure in place.

  • ✗

    Renew vendor contracts

    Why it's wrong here

    Contract renewal is a procurement and vendor-management activity driven by commercial cycles, unrelated to analysing an incident's timeline, root cause and lessons learned. It is tempting because incidents often expose third-party weaknesses, prompting contract renegotiation, but that remediation occurs after the review, not within it.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.