Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are essential components of an incident response plan? (Select two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Communication templates

Option A (Communication templates) is correct because an incident response plan must include pre-approved notification templates for internal stakeholders, customers, regulators, and media so that accurate, consistent messaging can be delivered quickly during a live incident without drafting communications under pressure. Option C (IR team roster and contact list) is correct because the plan must identify who is on the incident response team, their roles (e.g., incident commander, forensics lead, communications lead), and up-to-date 24/7 contact details so the team can be assembled immediately when an incident is declared. The remaining options are supporting or program-level artifacts rather than essential plan components: vendor risk assessment reports (B) belong to third-party risk management, network architecture diagrams (D) are useful reference documentation but not a required element of the plan itself, and an annual security awareness training schedule (E) is part of the broader security awareness program, not the incident response plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Communication templates

    Why this is correct

    Communication templates satisfy the stakeholder-notification constraint by pre-drafting regulatory, legal and executive messaging, so notifications occur within mandated breach-reporting windows rather than being composed under pressure. They also standardise severity-dependent escalation paths, ensuring consistent disclosure across jurisdictions and preventing inadvertent admission of liability during Microsoft Entra ID compromise investigations.

  • ✗

    Vendor risk assessment reports

    Why it's wrong here

    Vendor risk assessment reports belong to third-party risk management, not incident response planning. They tempt because supplier risk feeds business continuity and breach exposure, so they appear in broader resilience documentation — but an IR plan needs roles, escalation paths, communication procedures and containment steps.

  • ✓

    IR team roster and contact list

    Why this is correct

    The IR team roster and contact list identify who is accountable for each response function and how to reach them out of hours, satisfying the plan's requirement for defined roles and escalation paths. Without it, coordination collapses during the critical early containment window.

  • ✗

    Network architecture diagrams

    Why it's wrong here

    Network diagrams support troubleshooting and architecture review, but an IR plan needs roles, escalation criteria, communication procedures and containment steps. Diagrams tempt because responders genuinely consult topology during investigation, so they belong in supporting documentation — not as an essential plan component.

  • ✗

    Annual security awareness training schedule

    Why it's wrong here

    A training schedule is a security awareness programme artefact, not an IR plan component. It tempts because trained staff improve incident reporting and response quality, so awareness appears in overarching security programme documentation — yet the IR plan itself requires defined roles, escalation criteria, communication channels and containment procedures.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.