mediumMultiple Select
CISM Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of an effective incident response plan?
⚠ Common exam trap
ISACA often tests the distinction between the plan's structural components (like chain of command and communication plans) and operational tools or overly rigid scripts, tempting candidates to select automatic tools or exhaustive scripts as key components when they are not foundational to the plan's design.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A clear chain of command and escalation procedures.
Option A is correct because an effective incident response plan must define a clear chain of command and escalation procedures, ensuring that roles, decision authority, and handoff paths (for example, from Tier 1 to Tier 2 to the IR lead) are unambiguous during a high-pressure event. Option D is correct because a communication plan for internal and external stakeholders governs who is notified, when, and through which channels, covering obligations such as breach notification to regulators, customers, and law enforcement, and preventing conflicting or premature disclosures. Options B and C are not key components: automated detection and response tools are supporting technologies that enable the plan rather than constituting it, and predefined scripts for every possible incident are impractical since incidents vary and rigid scripts can hinder adaptive response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A clear chain of command and escalation procedures.
Why this is correct
A defined chain of command with escalation procedures ensures incidents are routed to the right authority quickly, preventing confusion, duplicated effort and delayed decisions. It establishes clear ownership and communication paths, which are essential for coordinated, timely response across technical and management teams.
- ✗
Automatic detection and response tools.
Why it's wrong here
Tools automate detection and response, but an incident response plan is a documented framework of roles, phases, communication and procedures; tooling supports it rather than constituting a component. It is tempting because automated detection accelerates containment, yet the plan must function independently of any specific product.
- ✗
Predefined response scripts for every possible incident.
Why it's wrong here
Scripts cannot cover every possible incident, so a plan built on exhaustive predefined scripts fails when novel threats arise; the plan instead defines phases, roles and escalation criteria. Predefined playbooks are tempting because they speed routine responses, but they supplement, not replace, the plan's flexible framework.
- ✓
A communication plan for internal and external stakeholders.
Why this is correct
A communication plan defines who notifies internal teams, customers, regulators and media, and when. Without it, disclosure is delayed or inconsistent, worsening regulatory and reputational impact. It is a core component alongside roles, escalation paths and containment procedures.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.