Home › Certifications › CISM › Incident Management — Readiness and Response
60 multiple-choice questions and 21 flashcards on Incident Management — Readiness and Response, about 15% of the CISM bank. Every one carries a written rationale.
Incident Management — Readiness and Response is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 60 of the bank's 400 multiple-choice questions — roughly 15% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
How does incident management differ from incident response?
Answer: B — Response is the tactical handling of an event; management is the program of preparation and improvement
B has the scope right: response is what the team does when an event occurs, while management is the surrounding program covering the plan, the team and its authorities, playbooks, exercises, communication arrangements, metrics and post-incident improvement. A and E deny a distinction the exam tests. C reverses the containment relationship. D invents a threshold that does not exist, since incident management applies across the full severity range, not only to declared disasters.
After a confirmed compromise of a domain controller, the response team wants to reimage the server immediately to restore service. Litigation is considered likely. The security manager's NEXT action should be to:
Answer: A — Direct that forensic images and volatile data be captured before rebuilding
A) Correct — where litigation is reasonably anticipated, preservation obligations attach, and capturing images and memory first costs little while destroying them is irreversible. B) is the technically fastest path and the classic trap; speed here forfeits evidence the organisation will need. C) tempts because major incidents escalate, but the preservation decision sits with the response plan and counsel, not the chief executive. D) freezes the response entirely; isolation plus preservation plus rebuild is the correct sequence, and audit is not the gating function.
Short-term containment differs from long-term containment in that short-term:
Answer: B — Stops immediate damage while a durable fix is engineered separately
B is the key: two-phase containment buys time without committing to the final architecture. A conflates containment with eradication. C ignores the second phase entirely. D overstates a specific tactic as a rule.
Crisis communication during a significant incident should be:
Answer: B — Pre-planned, single-voiced and consistent across all channels used
B is the key: one prepared voice, legally reviewed, protects trust and limits regulatory exposure. A produces contradictory statements. C reaches only one audience and bypasses legal review. D creates a vacuum that others will fill.
During a live intrusion, an engineer identifies the attacker's command-and-control domain and unilaterally blocks it at the perimeter without notifying the incident commander. The plan requires containment actions to be authorised. The security manager's PRIMARY concern is that:
Answer: B — The engineer acted outside the authorisation set by the plan
B) Correct — the governance failure is the bypass of documented authority; an unapproved action can destroy evidence, tip off the adversary, or collide with a wider containment strategy the commander is sequencing. A) is possible but secondary and speculative; effectiveness is assessed after authority is restored. C) tempts because emergency change records matter, but the response plan, not the CAB, governs incident authority. D) is a real operational risk and a good reason for authorisation, yet it is a consequence of the control failure rather than the primary concern itself.
Which of the following BEST demonstrates that incident management training has been effective?
Answer: D — Incident reporting rises and escalation time falls
D) Correct — effectiveness is behavioural: more suspected events reaching the team and reaching it faster is the outcome training is meant to produce. A) measures participation, not capability. B) measures recall immediately after instruction, which correlates poorly with behaviour under stress. C) tempts because fewer incidents sounds like success, but it may equally indicate reduced reporting or weaker detection.
Which condition MOST strongly indicates that an event should be reclassified from a security incident to a crisis requiring executive leadership?
Answer: A — Several critical services and external parties are affected
A) Correct — crisis status turns on enterprise-level consequence, particularly simultaneous impact on critical services and external parties, which requires decisions beyond the security function's authority. B) tempts because duration is a common trigger in some plans, but a long low-impact event is not a crisis. C) is an operational escalation to specialist support rather than a crisis declaration. D) is a strong indicator of reputational exposure and often accompanies a crisis, but attention alone is not the criterion.
What is the PRIMARY purpose of an incident response plan?
Answer: B — To define roles, authorities, procedures and communications before an incident occurs
B is the point of the plan: decisions about who leads, who may authorize disconnection, whom to notify and on what trigger must be made in advance, because they cannot be made well under pressure. A describes an output of the process, not its purpose. C is unattainable, since no plan prevents incidents. D confuses scope; the response plan handles the security event while continuity keeps the business running. E is a by-product of a credible plan rather than its objective.
Cyber-insurance value during an incident is BEST realized by:
Answer: A — Engaging the insurer and breach coach early and using panel vendors as required
A is the key: policies commonly condition coverage on prompt notice and approved vendors. B risks late-notice denial. C forfeits the cover already paid for. D relies on sales material rather than the policy wording.
An organization considers paying a ransomware demand. The PRIMARY governance issue is:
Answer: D — Legal, regulatory and sanctions exposure, needing executive sign-off
D is the key: payment can breach sanctions and reporting duties, so it is an executive decision made with counsel and recorded. A treats a governance decision as a logistics problem. B and C are downstream execution details.
4 cards from the 21 in this chapter.
Rank the main incident exercise types by rigour and state what each proves.
Checklist or walkthrough review proves documentation exists and is understood. Tabletop proves decision-making, roles and escalation logic under discussion. Simulation or functional exercise proves that procedures and tools work under time pressure. Full interruption or live test proves actual recovery in production conditions and carries real operational risk.
Why must notification decisions be made by legal and executive management rather than the incident response team?
Notification triggers legal, regulatory and contractual consequences and shapes liability and reputation, so it sits with counsel and executives who hold that accountability. The response team supplies validated facts on scope, data involved and timeline; deciding to notify — or holding a public statement — is not a technical determination.
Containment strategies?
Short-term (isolate quickly) vs long-term (preserve evidence + restore).
What is the difference between an event, an incident and a breach?
An event is any observable occurrence in a system. An incident is an event, or series of events, that actually or imminently jeopardises confidentiality, integrity or availability and requires response. A breach is an incident confirmed to have resulted in unauthorised access to or disclosure of protected data, which is what typically triggers notification obligations.
These are a sample. The full Incident Management — Readiness and Response chapter runs 81 items with per-chapter progress tracking, on the web and in the iOS app.