CISM Incident Management: 118 practice questions
12 of the 118 Incident Management questions in the Certsqill CISM bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CISM? Take the free 5-min readiness check →
1. Activate the incident response team: The organization's incident response policy requires board notification f
- Immediately notify the board of directors and legal counsel, since the potential volume of 50,000 records clearly exceeds the policy's defined breach notification threshold and demands immediate executive escalation.Incorrect. The policy specifies notification for 'confirmed' exfiltration. Notifying the board of an unconfirmed alert before initial investigation would trigger unnecessary escalation and may cause organizational disruption based on a false positive. Initial containment and investigation should precede board notification, with escalation occurring once the incident is confirmed.
- Submit a standard ticket to the IT operations team asking them to investigate the alert during normal business hours and provide a detailed written status report by the close of business on Monday.Incorrect. A potential breach of 50,000 customer credit card records is a Priority 1 security incident requiring immediate response, not a routine ticket. Routing it through normal IT operations with a 3-day SLA is grossly inadequate and would likely result in regulatory violations for failure to respond timely.
- Wait until Monday morning when the full incident response team is on site before taking any action, since the incident response policy formally requires confirmed exfiltration before a response begins.Incorrect. Waiting 60+ hours in a potential data breach situation is not appropriate. The time to contain a potential breach is critical—the longer you wait, the more data may be exfiltrated or the harder it becomes to preserve forensic evidence. The incident response process should begin immediately upon detecting a potential incident.
- Activate the incident response team, initiate containment procedures to stop any potential ongoing exfiltration, and preserve forensic evidence while the investigation confirms or rules out the suspected breach. ✓Correct. The first response to a potential data breach should always be containment to stop any ongoing harm, followed by evidence preservation to support investigation and legal proceedings. The fact that exfiltration is unconfirmed does not delay the initial response—it means the response proceeds as a precautionary measure until confirmation or denial. Waiting for confirmation before acting can result in additional data loss and destruction of forensic evidence.
Initial incident response always begins with containment and evidence preservation, regardless of confirmation status. Investigation confirms or denies, but containment cannot wait for confirmation.
2. BCP addresses how the organization continues critical: How should the CISM respond?
- BCP addresses how the organization continues critical business operations during a disruption while DRP addresses how IT systems are recovered afterward; both would be invoked concurrently for a data center flood, with the DRP recovering IT systems and the BCP maintaining business operations throughout the recovery period. ✓Correct. BCP is a broader plan covering how the entire organization maintains critical business functions during a disruption—including manual workarounds, alternative locations, communication plans, and business process continuity. DRP is a subset of BCP focused specifically on recovering IT infrastructure and systems. For a data center flood: the DRP would guide IT in recovering systems at the alternate site, while the BCP would guide business units in maintaining operations (manual procedures, customer communication, vendor notifications) during the IT recovery period. Both plans operate concurrently.
- BCP is strictly a long-term strategic recovery plan while DRP handles only short-term operational recovery; for a data center flood, therefore, just the DRP would be invoked because the event is fundamentally an IT infrastructure problem rather than a broader business continuity concern for the wider organization's overall operations.Incorrect. This characterization misdefines both plans. BCP is not about 'long-term' recovery—it governs maintaining business operations throughout the disruption period, which may be days or weeks. A data center flood affects business operations, not just IT infrastructure, so BCP must also be invoked to maintain business continuity during the IT recovery period.
- BCP and DRP are essentially the same document and the two terms are used interchangeably for regulatory and audit purposes; for a data center flood the combined DRP/BCP would simply be invoked as one unified plan to guide the organization's overall response and recovery from the incident.Incorrect. BCP and DRP are distinct plans with different scope, objectives, and audiences. Conflating them at the board level demonstrates a governance gap and may result in both plans being inadequately developed.
- DRP is the plan reserved specifically for natural disasters while BCP is the plan reserved specifically for cyber incidents; because a flood is by definition a natural disaster, only the DRP would be invoked to guide the organization's response to this particular data center event.Incorrect. This is a fundamental misclassification. BCP and DRP are distinguished by scope (business operations vs. IT systems), not by the type of disruptive event. Both plans may be applicable to natural disasters, cyber incidents, and other disruptions depending on their impact.
BCP maintains business operations during disruption; DRP recovers IT systems after disruption. Both are invoked concurrently for a data center disaster.
3. Complete forensic imaging of the server before allowing: What should the CISM recommend?
- Escalate the conflict to the CEO, as the CISM cannot make this decision without executive authorization.Incorrect. While executive awareness may be appropriate, escalating without a recommendation abdicates the CISM's professional responsibility to provide expert guidance. The CISM should provide a clear recommendation based on incident management best practices and legal risk, not simply pass the decision upward without context.
- Complete forensic imaging of the server before allowing any changes, and work with the business to identify alternative ways to meet the contract deadline. ✓Correct. In any incident potentially involving criminal activity or litigation, evidence preservation takes priority over operational convenience. The forensic imaging process (creating a bit-for-bit copy) preserves the evidence while allowing the original system to eventually be restored or the business data to be extracted for operational use. The CISM should complete forensic imaging first, then work with business stakeholders to find alternative ways to meet the contract deadline (extracting the business data from the forensic image, using backup copies, or negotiating deadline extensions with the counterparty).
- Support the legal team's request to wipe and rebuild the server immediately, as business continuity takes priority and the attacker is already gone.Incorrect. Wiping the server before forensic imaging destroys evidence that may be needed for criminal prosecution, civil litigation, and regulatory investigation. In an IP theft case, forensic evidence is critical for identifying the attacker, determining what was taken, and supporting legal remedies. The assumption 'the attacker is already gone' cannot be confirmed without forensic analysis.
- Allow the legal team to copy the business data off the server before wiping, as copying data preserves the information needed without requiring full forensic imaging.Incorrect. Copying business data off a compromised server is not equivalent to forensic imaging. Forensic evidence includes system logs, memory artifacts, file metadata, deleted files, and registry entries that are not captured by a simple file copy. This approach destroys forensic evidence while preserving only the operational data.
Evidence preservation through forensic imaging must precede operational restoration in incidents involving potential criminal activity or litigation. The forensic image allows both investigation and eventual data recovery.
4. Refer the journalist to the designated crisis: What is the CISM's MOST appropriate immediate action?
- Provide the journalist with a brief factual statement that the organization is aware of a technical issue and is working to resolve it, to prevent speculation and manage the narrative.Incorrect. While managing the public narrative is important, the CISM is not the designated spokesperson for media relations during a crisis. Providing a statement without CEO briefing, legal review, and coordination with the communications team could release legally sensitive information prematurely and undermine the organization's crisis communication strategy.
- Brief the CEO first, then prepare a detailed press release with full technical details of the incident to demonstrate transparency.Incorrect. Providing full technical details of an active security incident in a press release is contraindicated—it provides the attacker with confirmation of what was successful, what the organization has detected, and what actions are being taken. Crisis communications during active incidents use minimal technical disclosure. Legal review is also required before any public statement.
- Refer the journalist to the designated crisis communications spokesperson, brief the CEO immediately, and continue incident containment as the priority. ✓Correct. During a security incident, media relations should be handled exclusively by the designated crisis communications spokesperson (typically the PR/communications team or a designated executive). The CISM's primary responsibility is technical incident management and briefing the CEO/incident command. Referring the journalist to the proper spokesperson, immediately briefing the CEO (who cannot lead the response without being informed), and continuing containment operations are the correct concurrent priorities.
- Decline to comment to the journalist and continue focusing on containment, as media relations during an active incident are the CEO's responsibility.Incorrect. While declining to comment personally is appropriate, simply declining without redirecting the journalist to the designated spokesperson leaves a communications gap. More importantly, this answer does not address the need to immediately brief the CEO, which is a critical leadership and governance responsibility.
During incidents, media relations go to the designated crisis spokesperson, the CEO requires immediate briefing, and the CISM's primary focus remains technical incident management.
5. Identifying the control failures and process gaps: What is the CORRECT answer?
- Assigning clear personal accountability to each of the individuals whose specific errors enabled the incident, in order to deter future negligence and reinforce disciplined staff behavior across the organization.Incorrect. Post-incident reviews should follow a 'blameless' or 'just culture' model focused on system and process failures rather than individual blame. Assigning personal blame creates a culture where employees hide mistakes rather than reporting incidents early, undermining the security program. Accountability for remediation actions is appropriate; blame for the incident is counterproductive.
- Documenting the full incident timeline and the technical indicators of compromise so that those IOCs can be fed into the organization's future threat intelligence and detection engineering program.Incorrect. Documenting IOCs is a valuable tactical output of incident investigation, but it is not the most important outcome of a post-incident review. IOCs have limited value because attackers change their infrastructure frequently. The PIR's purpose is to improve the organization's capabilities, not primarily to document historical technical indicators.
- Determining the precise total financial impact of the incident so that the resulting figures can support the organization's cyber insurance claim and its internal accounting and financial reporting records.Incorrect. Quantifying financial impact is important for insurance claims, financial reporting, and risk quantification, but it is not the primary purpose of a post-incident review. The PIR is forward-looking—focused on improving future capabilities—not backward-looking financial accounting.
- Identifying the control failures and process gaps that enabled the incident, then implementing specific, prioritized remediation actions each assigned to a named owner along with a firm completion deadline. ✓Correct. The primary purpose of a post-incident review is to identify what failed and why, and to drive specific, accountable remediation actions that prevent recurrence. In this case, three specific failures were identified: email security control gaps, training gaps for a high-risk role, and a missing procedural control for wire transfers. Each failure should have a specific remediation action, an owner, and a deadline. This transforms the incident from a pure loss into an organizational improvement opportunity.
The primary purpose of a post-incident review is to identify control failures and process gaps, and to implement specific remediation actions that prevent recurrence.
6. Briefly and clearly communicate to the CEO: What should the CISM do?
- Pause all active response activities immediately until the CISM and the CEO can meet and align on a single joint response plan, so that the team does not execute conflicting instructions that work against one another or cause additional harm during the active ransomware incident.Incorrect. Pausing response activities during an active incident to achieve consensus causes additional harm. Ransomware actively encrypts data while response is paused. The CISM should continue response activities while managing the executive communication challenge concurrently, not sequentially.
- Follow the CEO's technical instructions immediately and without objection, on the basis that the CEO holds ultimate organizational authority and bears final accountability for whatever final outcome results from the organization's overall incident response effort and its handling.Incorrect. While the CEO has ultimate organizational authority, implementing technically incorrect actions during an incident because of authority pressure can cause irreversible harm (evidence destruction, extended outage, incomplete containment). The CISM has a professional obligation to clearly communicate the risks of proposed actions before implementing them.
- Quietly ask individual security team members to politely redirect the CEO toward the crisis management team, while the responders continue executing the original planned containment strategy without directly confronting the CEO about the disagreement or the technical risks his instructions create.Incorrect. Redirecting the CEO without direct communication from the CISM is disrespectful and ineffective. The CEO will likely override this redirection. More importantly, the CEO's presence in the SOC may reflect a legitimate concern about the pace of response that the CISM should acknowledge and address directly.
- Briefly and clearly communicate to the CEO that the proposed actions risk destroying forensic evidence and undermining the containment strategy, present the CISM's recommended approach, and request decision authority for technical execution within the CEO's overall strategic direction. ✓Correct. During a crisis, clear communication up the chain of command is critical even when it involves respectfully pushing back on authority. The CISM should: (1) Acknowledge the CEO's presence and intent (control, speed, decisiveness), (2) Clearly and concisely communicate the specific risk of the proposed actions (evidence destruction, containment gaps), (3) Present the existing containment strategy and its rationale, (4) Request that the CEO provide strategic direction (priorities: speed vs. evidence preservation?) while delegating technical execution decisions to the incident commander (CISM). This maintains the CEO's authority while ensuring technically sound execution.
The CISM should clearly communicate the risk of the CEO's proposed actions, present the planned strategy, and request technical execution authority within the CEO's strategic direction—maintaining authority respect while ensuring sound technical judgment.
7. The plan was developed in isolation by the IT security: What is the MOST significant gap in this plan?
- The plan was developed in isolation by the IT security team and lacks cross-functional input, leaving out critical decision-making authorities, communication protocols, and non-technical response actions required for effective incident management. ✓Correct. Effective incident response requires coordinated action across multiple organizational functions: Legal—legal obligations, regulatory notification, evidence preservation for litigation, privilege protection during investigation. HR—employee-related incidents (insider threat, disciplinary actions, labor law compliance). Communications—external stakeholder notification, media management, customer communication. Business unit leaders—operational decisions, resource authorization, business continuity decisions during recovery. An IT-only plan addresses only the technical response dimension and will fail when incidents require legal holds, regulatory notifications, executive decisions about disclosure, or HR involvement in insider threat cases.
- Because the plan was written solely by the IT security team, it lacks the formal organizational authority needed to direct non-IT personnel and other departments during a serious enterprise-wide incident.Incorrect. Authority for the incident response plan comes from executive approval, not from who wrote it. The plan can gain organizational authority through executive endorsement regardless of its authors. The problem is not authorship authority but substantive content gaps from missing functional perspectives.
- The plan omits the regulatory breach-notification procedures that applicable breach notification laws require, exposing the organization to penalties for late or missing statutory notifications after an incident.Incorrect. Regulatory notification is one specific gap likely resulting from the missing Legal review, but it is a symptom of the broader gap, not the root cause. The most significant issue is that the plan was developed without cross-functional involvement, making it incomplete across multiple dimensions.
- The plan has not undergone tabletop exercise validation, which many frameworks treat as a prerequisite before an incident response plan can be considered operationally ready and effective.Incorrect. While tabletop exercise validation is important, it is a testing and validation step. The more fundamental gap is that the plan itself is incomplete due to missing cross-functional input. Testing an incomplete plan will not identify all gaps.
An IT-only incident response plan lacks critical cross-functional components: legal obligations, regulatory notification, HR processes, communication protocols, and business decision authorities.
8. Conduct a tabletop exercise with key stakeholders walking: The CISM must select the MOST appropriate testing a
- Review the written IR plan in detail with the security team to confirm everyone understands their roles, since a thorough plan review is sufficient for this first testing stage.Incorrect. Written plan review identifies document completeness but not operational readiness. Teams that have reviewed a plan may still fail to execute it effectively under incident conditions. Testing requires simulating decision-making and coordination under pressure, which written review does not accomplish.
- Conduct a tabletop exercise with key stakeholders walking through a ransomware scenario, identifying gaps and decision points without involving production systems. ✓Correct. For organizations new to IR testing, a tabletop exercise is the appropriate starting point. A tabletop exercise: (1) Involves key stakeholders discussing their response actions to a simulated scenario without touching production systems, (2) Reveals process gaps, unclear decision authorities, missing communication plans, and incomplete procedures without production risk, (3) Builds shared understanding of roles and responsibilities across IT, Legal, HR, and Communications, (4) Produces a prioritized list of improvements that can be addressed before more advanced testing. The tabletop → functional drill → full-scale exercise progression matches organizational testing maturity.
- Conduct a penetration test to simulate the ransomware attack phase, then observe the IR team's response to the findings.Incorrect. A penetration test simulates the attacker's perspective (finding vulnerabilities) not the incident response perspective (responding to a detected incident). These serve different purposes. A penetration test would not test the IR plan's procedures, decision authorities, or communication protocols.
- Conduct a full live-fire simulation with simulated ransomware deployed into the production environment, since this approach provides the most realistic possible test of the response.Incorrect. A live-fire production simulation is the most advanced form of IR testing and is completely inappropriate for an organization that has never tested its IR plan. The risk of unintended production impact is unacceptable, and participants who have never walked through the plan will be unable to evaluate gaps effectively. Testing maturity must be built progressively.
Organizations new to IR testing should start with tabletop exercises that walk stakeholders through scenarios without production risk, revealing process and coordination gaps before advancing to more complex testing.
9. A → D → B → C: What is the CORRECT recovery sequence?
- B → D → A → C (ERP first due to financial data integrity requirements, then revenue, then authentication, then communication).Incorrect. Like option A, this sequence attempts to recover application systems before the authentication infrastructure (Active Directory) they depend on. The ERP system requires Active Directory for user authentication and cannot be fully recovered before AD is operational.
- A → B → D → C (authentication, then strictest RTO first in order).Incorrect. While recovering Active Directory first is correct, this sequence prioritizes the ERP (4-hour RTO) over the e-commerce platform (2-hour RTO). Given the e-commerce platform's shorter RTO and $50K/hour revenue impact, it should be prioritized over the ERP once AD is restored.
- A → D → B → C (authentication infrastructure first, then revenue-generating, then business operations, then communication). ✓Correct. Recovery sequencing must account for system dependencies before RTO targets. Active Directory must be recovered first because all other systems depend on it for authentication. Once Active Directory is operational, the e-commerce platform (D) is recovered next—its 2-hour RTO and $50K/hour revenue loss creates the highest time-sensitive business impact among the remaining systems. The ERP (B) follows with its 4-hour RTO. Email (C) has the most flexibility with an 8-hour RTO and lower direct revenue impact. This sequence: resolves infrastructure dependency → maximizes revenue recovery → restores business operations → restores communication.
- D → B → A → C (revenue first, then business operations, then infrastructure, then communication).Incorrect. Attempting to recover the e-commerce platform (D) before Active Directory (A) is operationally impossible—e-commerce platform authentication depends on Active Directory. Recovering revenue-generating systems before the authentication infrastructure they depend on is a sequencing error that will cause recovery failure.
Recovery sequencing requires resolving infrastructure dependencies before application systems. Active Directory must be restored first as it is a dependency for all other system recoveries.
10. GDPR requires notification to the EU supervisory authority: Which statement BEST reflects the notification obl
- Because the organization is headquartered in the United States, U.S. regulations take precedence in this incident, and GDPR supervisory-authority notifications remain effectively voluntary for a U.S.-based company that is handling only a comparatively small number of EU customer records.Incorrect. GDPR applies to any organization that processes personal data of EU residents, regardless of where the organization is headquartered. The 1,500 EU customers' data is subject to GDPR, and the 72-hour supervisory authority notification requirement is mandatory, not voluntary. Non-compliance can result in fines of up to 4% of global annual turnover.
- Notify every affected customer in both the U.S. and the EU immediately, within 24 hours of detection, in order to satisfy the single most stringent notification timeline found across all applicable regulations.Incorrect. No applicable regulation in this scenario requires customer notification within 24 hours. Notifying customers prematurely (before completing an initial assessment and preparing adequate support) can cause unnecessary panic, increase support call volume before response is ready, and potentially interfere with the investigation. Notification timing must balance legal obligations with operational readiness.
- Complete the full forensic investigation first in order to precisely scope the breach before issuing any external notifications, since regulators will generally accept somewhat delayed notifications while a thorough investigation remains actively in progress.Incorrect. Under GDPR, the 72-hour notification clock runs from when the organization 'becomes aware' of the breach—not when the investigation is complete. A complete picture is not required; the regulation expects notification with available information and supplementary updates as more becomes known. Waiting for complete investigation will cause GDPR notification to be late.
- GDPR requires notification to the EU supervisory authority within 72 hours of discovery; U.S. state breach notification laws vary (typically 30-90 days) and GLBA requires notification 'as soon as possible' after discovery; these obligations run concurrently and may require separate notifications. ✓Correct. The notification obligations are concurrent and distinct: GDPR (EU): Notification to the relevant EU supervisory authority (not necessarily customers) is required within 72 hours of becoming aware of the breach—the clock started at 9 AM Monday, creating a Wednesday morning deadline for supervisory authority notification. Customer notification under GDPR is required 'without undue delay' if the breach is likely to result in high risk to individuals. U.S. State laws: Vary by state, typically 30-90 days, apply to the U.S. customers. GLBA (FTC Safeguards Rule): Requires customer notification 'as soon as possible' and notifying FTC within 30 days for incidents affecting 500+ customers. These timelines run concurrently, not sequentially. The CISM must track each deadline separately.
Multiple breach notification obligations run concurrently with different timelines: GDPR supervisory authority within 72 hours of awareness, U.S. state laws within 30-90 days, GLBA as soon as possible. Each must be tracked separately.
11. Quietly preserve forensic evidence of the exfiltration: What should the CISM do FIRST?
- Quietly preserve forensic evidence of the exfiltration activity, then consult with Legal and HR before taking any action that affects the employee. ✓Correct. The first action in a potential insider threat case is evidence preservation—capturing the DLP logs, access logs, and network activity records before they age out or are overwritten. The second step is consulting Legal (to assess legal exposure and investigation authority) and HR (to understand labor law requirements, investigation procedures, and the impact of the employee's resignation status). Acting against the employee—access revocation, interview, termination—before Legal and HR alignment risks legal liability. The resignation timeline adds urgency: evidence must be preserved and a plan developed before the employee's departure.
- Block all cloud storage access across the entire organization to prevent any further potential exfiltration while the investigation into the employee's activity proceeds.Incorrect. Blocking cloud storage organization-wide is a disproportionate operational response that would disrupt all legitimate use while potentially signaling to the subject that they are under investigation. Targeted monitoring of the specific employee's activity is appropriate; organization-wide disruption is not.
- Immediately terminate the employee's system access and confiscate their assigned laptop, holding both pending the outcome of a full internal investigation.Incorrect. Immediate termination of access and laptop confiscation before investigation may violate labor laws, trigger wrongful termination claims, and destroy the collaborative relationship needed to determine whether this is a genuine insider threat or authorized business activity. It also tips off the employee before evidence is secured and may interfere with forensic investigation.
- Contact the employee's direct manager to ask whether the large document upload was authorized and expected as a normal part of their finance job duties.Incorrect. Contacting the manager tips off the employee and may result in destruction of additional evidence. Investigation of potential insider threats should be conducted covertly until the CISM has Legal and HR alignment on the investigation approach.
Insider threat investigations require evidence preservation first, then Legal and HR consultation before any action affecting the employee—acting without this coordination creates legal and investigation risk.
12. Clearly defined roles: Which element is MOST critical to include in an incident response plan to ensure it rem
- A comprehensive list of all known threat actors currently targeting the organization's specific industry sector.Incorrect because threat intelligence is an input to incident response but is not a core plan element. Threat actor lists can change rapidly and are not appropriate to embed in the plan itself.
- Technical specifications for all deployed security tools and their default configurations.Incorrect because tool specifications are operational documentation. The incident response plan focuses on process, roles, and decision frameworks, not technical tool configurations.
- Clearly defined roles, responsibilities, and escalation paths documented for all incident response team members. ✓Correct because during an actual incident, confusion about who does what wastes critical response time. Predefined roles and escalation paths allow the team to act decisively without debate during high-stress situations.
- A comprehensive inventory of every organizational IT asset annotated with its current patch level.Incorrect because while asset inventories support incident response, they are not part of the incident response plan itself. They are a supporting tool, not a plan element.
Clearly defined roles, responsibilities, and escalation paths are foundational to an effective incident response plan because they eliminate confusion during high-pressure events.
106 more Incident Management questions
The remaining 106 questions in this domain are part of the full CISM bank — 497 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CISM readiness — freeOther CISM domains
- Information Security Governance — 131 questions →
- Information Security Risk Management — 124 questions →
- Information Security Program — 124 questions →
- All 497 CISM questions →