Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?

⚠ Common exam trap

Test-takers frequently confuse the strategic responsibilities of the CMT with the tactical or operational tasks of the technical incident response team, leading candidates to select hands-on actions like log analysis or backup restoration instead of high-level decision-making roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Approving external communications and public statements

Option B is correct because the crisis management team owns the incident's external-facing messaging, ensuring that all press releases, customer notifications, and regulatory disclosures are reviewed and approved before release to protect the organization's reputation and legal standing. Option E is correct because the CMT is a strategic decision-making body that determines whether to invoke business continuity or disaster recovery plans, weighing operational impact, safety, and financial consequences rather than performing hands-on technical work. Options A, C, and D are incorrect because restoring backups, analyzing logs to find the attack vector, and conducting forensic analysis of compromised systems are tactical, technical tasks performed by incident response handlers, forensic analysts, and system administrators, not by the strategic CMT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restoring backups of affected servers

    Why it's wrong here

    Restoring backups is tactical recovery work owned by IT operations or the recovery team, executed after the CMT sets priorities. It is tempting because recovery is central to incident response, but the CMT's remit covers strategic coordination, communications and business decisions, not hands-on server restoration.

  • ✓

    Approving external communications and public statements

    Why this is correct

    The CMT owns reputational and stakeholder impact, so it approves external communications and public statements, ensuring legal, regulatory and messaging consistency. This satisfies the stem by keeping disclosure decisions at strategic level rather than with technical responders, who lack authority to commit the organisation publicly.

  • ✗

    Analyzing log files to identify the attack vector

    Why it's wrong here

    Log analysis to determine the attack vector is a hands-on technical investigation owned by the SOC or incident response analysts, whereas the CMT sets direction and manages business consequences. It tempts because attack-vector findings inform CMT decisions, and would be the right answer if the question asked who performs technical root-cause analysis.

  • ✗

    Conducting technical forensic analysis of compromised systems

    Why it's wrong here

    Forensic examination of compromised hosts is an operational task performed by incident responders and forensic specialists, not the CMT, which coordinates business impact, communications and strategic decisions. It tempts because forensic evidence does feed CMT briefings, and would be correct if the question asked who collects evidence for legal or root-cause purposes.

  • ✓

    Making strategic decisions about business continuity activation

    Why this is correct

    Activating business continuity is a strategic, enterprise-wide decision affecting customers, revenue and recovery priorities, so it sits with the CMT rather than the technical response team. This satisfies the stem by placing authority for continuity activation where cross-functional impact and resource trade-offs can be weighed.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.