CISM Incident Management Practice Question
Which TWO of the following are essential components of an incident response programme?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response plan
An incident response plan (A) is essential because it defines the documented, step-by-step procedures, roles, communication paths, and escalation criteria that guide the team through detecting, containing, eradicating, and recovering from a security incident. An incident response policy (B) is equally essential because it is the governing document that establishes the organization's mandate, scope, objectives, authority, and management commitment for incident handling, which the plan then implements. Together, the policy provides the 'why and who' while the plan provides the 'how and when,' forming the foundational pair of any incident response programme. By contrast, an annual penetration test (C) and a vulnerability scanning schedule (D) are proactive vulnerability-management activities that feed the programme but are not core structural components of it, and security awareness training (E) is a preventive control that supports the programme rather than constituting an essential incident response component.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident response plan
Why this is correct
The incident response plan is an essential programme component, defining scope, roles, escalation paths, communication procedures and response phases. Without it, teams lack a coordinated, repeatable approach to detecting, containing and recovering from incidents, undermining the entire programme's effectiveness.
- ✓
Incident response policy
Why this is correct
An incident response policy is essential because it establishes the authority, scope, and mandate for the entire programme, defining roles, escalation paths, and management commitment. Without this governing document, response activities lack formal approval and consistency, so it satisfies the requirement for a foundational component.
- ✗
Annual penetration test
Why it's wrong here
Penetration testing is a proactive assurance activity that identifies exploitable weaknesses before incidents; it neither detects, contains, nor recovers from live incidents. It is tempting because pen test findings do feed remediation and hardening, which is the correct choice when the question asks about vulnerability management rather than response.
- ✗
Vulnerability scanning schedule
Why it's wrong here
A scanning schedule is continuous vulnerability management, identifying weaknesses proactively; it does not define response roles, escalation paths, or containment procedures. It is tempting because scan output can trigger incident investigations, making it the right answer when the question concerns vulnerability management rather than incident response.
- ✗
Security awareness training
Why it's wrong here
Awareness training reduces the likelihood of incidents through user behaviour; it is a preventive programme element, not a response capability covering preparation, detection, containment, eradication and recovery. It is tempting because trained users report incidents faster, making it correct when the question addresses prevention or security culture.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.