Courseiva
Incident Management →mediumMultiple Select

CISM Incident Management Practice Question

Which TWO of the following are required components of an incident response programme according to best practices? (Select two.)

⚠ Common exam trap

A common trap in CISM is distinguishing between the policy (the 'what' and 'why') and the plan (the 'how'), leading candidates to select operational items like contact lists or templates instead of the mandatory governance components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident response policy

Option B (Incident response policy) is correct because best-practice frameworks such as NIST SP 800-61 and ISO/IEC 27035 require a formally approved policy that establishes the authority, scope, objectives, and management commitment for the incident response capability. Option C (Incident response plan) is correct because the plan is the documented, actionable set of procedures—roles, phases (preparation, detection and analysis, containment, eradication, recovery, post-incident activity), and escalation paths—that operationalizes the policy. The remaining items are supporting artifacts rather than required programme components: an IR team roster (A), communication templates (D), and a vendor contacts list (E) are useful appendices or resources referenced by the plan, but they are not themselves mandatory components of an incident response programme.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IR team roster

    Why it's wrong here

    A roster names individuals, yet the required component is defined roles and responsibilities within the incident response plan, not a personnel list. It is tempting because staffing feels fundamental, and would be correct when assigning on-call responders under an approved plan.

  • ✓

    Incident response policy

    Why this is correct

    An incident response policy supplies the mandated authority, scope and governance framework that best practice requires before any procedural or technical capability is built. It defines roles, escalation thresholds and management commitment, satisfying the programme's foundational requirement. Without it, plans and playbooks lack approved direction, so this option is a required component.

  • ✓

    Incident response plan

    Why this is correct

    Best practise frameworks (NIST, ISO 27035) treat a documented incident response plan as a required programme component, since it defines roles, escalation paths and procedures before an incident occurs. Without it, response activity is ad hoc and cannot satisfy the stem's requirement for a recognised component.

  • ✗

    Communication templates

    Why it's wrong here

    Templates are an operational convenience for notifying stakeholders, not a required programme component; best practice mandates a documented plan, team, and testing. They are tempting because they speed up breach notification, and would be correct when supporting an already-established communications plan.

  • ✗

    Vendor contacts list

    Why it's wrong here

    A vendor contacts list supports third-party escalation but is not a required component; the programme needs defined roles, plan, and testing. It is tempting because external suppliers often assist recovery, and would be correct as an annex once the core incident response plan exists.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.