easyMultiple Select
CISM Practice Question: Which THREE steps are essential in the…
Which THREE steps are essential in the post-incident review process?
⚠ Common exam trap
ISACA CISM often tests the distinction between a constructive, process-oriented review and a blame-seeking exercise; the trap here is that candidates may mistakenly think 'assigning blame' is necessary for accountability, when in fact it undermines the entire purpose of the review.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify lessons learned and process improvements
Option A is correct because the post-incident review must capture lessons learned and identify concrete process improvements so the organization does not repeat the same mistakes. Option B is correct because findings from the review should be fed back into the incident response plan, updating playbooks, contact lists, and procedures to reflect what actually worked and what failed. Option D is correct because a root cause analysis is essential to determine the underlying technical or procedural cause of the incident rather than just its symptoms, enabling effective remediation. Option C is not part of the process because post-incident reviews are blameless, focusing on systemic causes rather than punishing individuals, which would discourage honest reporting. Option E is unrelated because renewing vendor contracts is a procurement activity, not a step in reviewing and learning from an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify lessons learned and process improvements
Why this is correct
Capturing lessons learned converts the incident timeline and response actions into documented improvements, closing the feedback loop that distinguishes a post-incident review from mere incident closure. Without this step, the review produces no actionable change to controls, monitoring or response procedures.
- ✓
Update the incident response plan
Why this is correct
Feeding review findings back into the incident response plan keeps the documented procedures current, so the next response reflects what actually worked and what failed. This satisfies the review's purpose of improving future capability rather than only documenting the past event.
- ✗
Assign blame for the incident
Why it's wrong here
Post-incident review exists to find root cause and improve controls, so blaming individuals suppresses reporting and hides systemic weaknesses. It is tempting because accountability feels like a natural part of incident handling, and disciplinary follow-up is a separate HR matter, not a review step.
- ✓
Conduct a root cause analysis
Why this is correct
Root cause analysis determines the underlying weakness, such as an unpatched service or misconfigured control, that allowed the incident. Addressing that cause prevents recurrence, which is the review's central objective; treating only symptoms leaves the same exposure in place.
- ✗
Renew vendor contracts
Why it's wrong here
Contract renewal is a procurement and vendor-management activity driven by commercial cycles, unrelated to analysing an incident's timeline, root cause and lessons learned. It is tempting because incidents often expose third-party weaknesses, prompting contract renegotiation, but that remediation occurs after the review, not within it.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.