Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are essential components of an incident response programme?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident response plan

An incident response plan (A) is essential because it defines the documented, step-by-step procedures, roles, communication paths, and escalation criteria that guide the team through detecting, containing, eradicating, and recovering from a security incident. An incident response policy (B) is equally essential because it is the governing document that establishes the organization's mandate, scope, objectives, authority, and management commitment for incident handling, which the plan then implements. Together, the policy provides the 'why and who' while the plan provides the 'how and when,' forming the foundational pair of any incident response programme. By contrast, an annual penetration test (C) and a vulnerability scanning schedule (D) are proactive vulnerability-management activities that feed the programme but are not core structural components of it, and security awareness training (E) is a preventive control that supports the programme rather than constituting an essential incident response component.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident response plan

    Why this is correct

    The incident response plan is an essential programme component, defining scope, roles, escalation paths, communication procedures and response phases. Without it, teams lack a coordinated, repeatable approach to detecting, containing and recovering from incidents, undermining the entire programme's effectiveness.

  • ✓

    Incident response policy

    Why this is correct

    An incident response policy is essential because it establishes the authority, scope, and mandate for the entire programme, defining roles, escalation paths, and management commitment. Without this governing document, response activities lack formal approval and consistency, so it satisfies the requirement for a foundational component.

  • ✗

    Annual penetration test

    Why it's wrong here

    Penetration testing is a proactive assurance activity that identifies exploitable weaknesses before incidents; it neither detects, contains, nor recovers from live incidents. It is tempting because pen test findings do feed remediation and hardening, which is the correct choice when the question asks about vulnerability management rather than response.

  • ✗

    Vulnerability scanning schedule

    Why it's wrong here

    A scanning schedule is continuous vulnerability management, identifying weaknesses proactively; it does not define response roles, escalation paths, or containment procedures. It is tempting because scan output can trigger incident investigations, making it the right answer when the question concerns vulnerability management rather than incident response.

  • ✗

    Security awareness training

    Why it's wrong here

    Awareness training reduces the likelihood of incidents through user behaviour; it is a preventive programme element, not a response capability covering preparation, detection, containment, eradication and recovery. It is tempting because trained users report incidents faster, making it correct when the question addresses prevention or security culture.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.