CISM Incident Management Practice Question
Which TWO of the following are key responsibilities of the crisis management team (CMT) during a major cybersecurity incident?
⚠ Common exam trap
Test-takers frequently confuse the strategic responsibilities of the CMT with the tactical or operational tasks of the technical incident response team, leading candidates to select hands-on actions like log analysis or backup restoration instead of high-level decision-making roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approving external communications and public statements
Option B is correct because the crisis management team owns the incident's external-facing messaging, ensuring that all press releases, customer notifications, and regulatory disclosures are reviewed and approved before release to protect the organization's reputation and legal standing. Option E is correct because the CMT is a strategic decision-making body that determines whether to invoke business continuity or disaster recovery plans, weighing operational impact, safety, and financial consequences rather than performing hands-on technical work. Options A, C, and D are incorrect because restoring backups, analyzing logs to find the attack vector, and conducting forensic analysis of compromised systems are tactical, technical tasks performed by incident response handlers, forensic analysts, and system administrators, not by the strategic CMT.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restoring backups of affected servers
Why it's wrong here
Restoring backups is tactical recovery work owned by IT operations or the recovery team, executed after the CMT sets priorities. It is tempting because recovery is central to incident response, but the CMT's remit covers strategic coordination, communications and business decisions, not hands-on server restoration.
- ✓
Approving external communications and public statements
Why this is correct
The CMT owns reputational and stakeholder impact, so it approves external communications and public statements, ensuring legal, regulatory and messaging consistency. This satisfies the stem by keeping disclosure decisions at strategic level rather than with technical responders, who lack authority to commit the organisation publicly.
- ✗
Analyzing log files to identify the attack vector
Why it's wrong here
Log analysis to determine the attack vector is a hands-on technical investigation owned by the SOC or incident response analysts, whereas the CMT sets direction and manages business consequences. It tempts because attack-vector findings inform CMT decisions, and would be the right answer if the question asked who performs technical root-cause analysis.
- ✗
Conducting technical forensic analysis of compromised systems
Why it's wrong here
Forensic examination of compromised hosts is an operational task performed by incident responders and forensic specialists, not the CMT, which coordinates business impact, communications and strategic decisions. It tempts because forensic evidence does feed CMT briefings, and would be correct if the question asked who collects evidence for legal or root-cause purposes.
- ✓
Making strategic decisions about business continuity activation
Why this is correct
Activating business continuity is a strategic, enterprise-wide decision affecting customers, revenue and recovery priorities, so it sits with the CMT rather than the technical response team. This satisfies the stem by placing authority for continuity activation where cross-functional impact and resource trade-offs can be weighed.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.