Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Communication templates

Communication templates (C) are an essential IR plan component because during an incident responders must notify stakeholders, legal, regulators, and customers quickly and consistently, and pre-approved templates prevent delays and wording errors under pressure. The IR team roster and contact list (E) is also essential because the plan must identify who is on the incident response team and how to reach them (including after-hours and escalation contacts) so the team can be assembled immediately. Detailed network architecture diagrams (B) and vendor risk assessment reports (A) are valuable supporting artifacts for preparation and investigation, but they are not core components of the IR plan itself. A ransomware playbook (D) is a useful specialized procedure, yet it is only one scenario-specific playbook rather than a foundational element required in every IR plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vendor risk assessment reports

    Why it's wrong here

    Vendor risk assessments feed third-party risk management, not incident response planning. They are correct when evaluating supplier security posture, but an IR plan needs escalation contacts, roles, and containment and recovery procedures rather than procurement due-diligence artefacts.

  • ✗

    Detailed network architecture diagrams

    Why it's wrong here

    Network diagrams support preparation and impact assessment but are reference material, not an essential IR plan component. They belong in architecture documentation; an IR plan requires defined roles, communication paths, and phased procedures for detection, containment, eradication and recovery.

  • ✓

    Communication templates

    Why this is correct

    Pre-approved communication templates let the IR team notify stakeholders, regulators and customers quickly and consistently during a high-pressure incident, satisfying the plan's requirement for defined escalation and messaging procedures rather than improvising statements under time pressure.

  • ✗

    Playbook for ransomware incidents

    Why it's wrong here

    A ransomware playbook is a valuable scenario-specific annex, but the question asks for essential components present in every IR plan. Playbooks are the right choice when building response runbooks for named threats; the core plan needs generic phases, roles and communication procedures.

  • ✓

    IR team roster and contact list

    Why this is correct

    A current IR team roster with contact details ensures the right responders can be reached immediately, satisfying the plan's need for defined roles, escalation paths and 24/7 reachability so containment is not delayed by hunting for names.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.