CISM Incident Management Practice Question
Which TWO of the following are essential components of an incident response plan? (Select two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Communication templates
Option A (Communication templates) is correct because an incident response plan must include pre-approved notification templates for internal stakeholders, customers, regulators, and media so that accurate, consistent messaging can be delivered quickly during a live incident without drafting communications under pressure. Option C (IR team roster and contact list) is correct because the plan must identify who is on the incident response team, their roles (e.g., incident commander, forensics lead, communications lead), and up-to-date 24/7 contact details so the team can be assembled immediately when an incident is declared. The remaining options are supporting or program-level artifacts rather than essential plan components: vendor risk assessment reports (B) belong to third-party risk management, network architecture diagrams (D) are useful reference documentation but not a required element of the plan itself, and an annual security awareness training schedule (E) is part of the broader security awareness program, not the incident response plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Communication templates
Why this is correct
Communication templates satisfy the stakeholder-notification constraint by pre-drafting regulatory, legal and executive messaging, so notifications occur within mandated breach-reporting windows rather than being composed under pressure. They also standardise severity-dependent escalation paths, ensuring consistent disclosure across jurisdictions and preventing inadvertent admission of liability during Microsoft Entra ID compromise investigations.
- ✗
Vendor risk assessment reports
Why it's wrong here
Vendor risk assessment reports belong to third-party risk management, not incident response planning. They tempt because supplier risk feeds business continuity and breach exposure, so they appear in broader resilience documentation — but an IR plan needs roles, escalation paths, communication procedures and containment steps.
- ✓
IR team roster and contact list
Why this is correct
The IR team roster and contact list identify who is accountable for each response function and how to reach them out of hours, satisfying the plan's requirement for defined roles and escalation paths. Without it, coordination collapses during the critical early containment window.
- ✗
Network architecture diagrams
Why it's wrong here
Network diagrams support troubleshooting and architecture review, but an IR plan needs roles, escalation criteria, communication procedures and containment steps. Diagrams tempt because responders genuinely consult topology during investigation, so they belong in supporting documentation — not as an essential plan component.
- ✗
Annual security awareness training schedule
Why it's wrong here
A training schedule is a security awareness programme artefact, not an IR plan component. It tempts because trained staff improve incident reporting and response quality, so awareness appears in overarching security programme documentation — yet the IR plan itself requires defined roles, escalation criteria, communication channels and containment procedures.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.