Courseiva
Incident Management →hardMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are key considerations when managing an external forensics firm during an incident? (Select TWO)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maintaining chain of custody for all evidence

Option C is correct because maintaining chain of custody is essential when an external forensics firm handles evidence; documented, unbroken custody records ensure the evidence remains admissible in legal or disciplinary proceedings and prevents tampering or spoliation. Option D is correct because a clear scope of work plus agreed evidence-handling procedures define what the firm will investigate, how it will collect and preserve data, and what deliverables and timelines apply, preventing misunderstandings and unauthorized actions. The unmarked options do not belong: A is wrong because containment decisions should remain with the incident response team or management under the organization's authority, not be delegated independently to the forensics firm; B is wrong because media communications must go through the organization's designated spokesperson or PR/legal team, not the external firm; and E is wrong because requiring only proprietary tools is unnecessary and can hinder analysis, whereas validated, forensically sound tools and documented methods are what matter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allowing the firm to make independent decisions on containment

    Why it's wrong here

    Containment decisions remain with the incident response team and management, since the firm provides investigation and evidence handling, not business risk ownership. Delegating containment is tempting when the firm's expertise seems authoritative, yet it would bypass the organisation's accountability and could disrupt operations unnecessarily.

  • ✗

    Having the firm report directly to the media

    Why it's wrong here

    Media communication stays with the organisation's designated spokesperson and legal counsel, preserving privilege and message control; the firm supplies technical findings. Direct media reporting tempts when transparency is prized, but it risks disclosing sensitive incident details and conflicting public statements.

  • ✓

    Maintaining chain of custody for all evidence

    Why this is correct

    Chain of custody preserves evidence integrity so it remains admissible in legal or disciplinary proceedings. When an external firm handles artefacts, unbroken documented transfer records satisfy the evidentiary constraint the scenario demands, preventing challenges to forensic findings.

  • ✓

    Defining the scope of work and evidence handling procedures

    Why this is correct

    Defining scope and evidence procedures preserves evidential integrity and admissibility, satisfying the chain-of-custody constraint. A written engagement scope limits the firm to authorised systems, preventing over-collection that could breach privacy obligations or taint findings. This contractual clarity also fixes deliverables and timelines, enabling the CISO to direct the investigation rather than cede control.

  • ✗

    Ensuring the firm uses only proprietary tools

    Why it's wrong here

    Mandating proprietary tools risks unreadable evidence and vendor lock-in, whereas forensic validity depends on accepted, documented tooling and repeatable methodology. It tempts because standardised tooling sounds controlled, but proprietary formats can obstruct court admissibility and independent verification.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.