CoStudy

HomeCertificationsCISM › Incident Management — Readiness and Response

Incident Management — Readiness and Response — CISM practice questions

60 multiple-choice questions and 21 flashcards on Incident Management — Readiness and Response, about 15% of the CISM bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Incident Management — Readiness and Response is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 60 of the bank's 400 multiple-choice questions — roughly 15% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Incident Management — Readiness and Response practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

How does incident management differ from incident response?

  1. The terms are interchangeable and describe the same activities within the information security program
  2. Response is the tactical handling of an event; management is the program of preparation and improvement
  3. Response is the broader program and incident management is one activity performed inside it
  4. Management refers to routine daily operations while response applies only to declared disasters
  5. No distinction exists, as both are governed by the same plan and executed by the same people

Answer: B — Response is the tactical handling of an event; management is the program of preparation and improvement

B has the scope right: response is what the team does when an event occurs, while management is the surrounding program covering the plan, the team and its authorities, playbooks, exercises, communication arrangements, metrics and post-incident improvement. A and E deny a distinction the exam tests. C reverses the containment relationship. D invents a threshold that does not exist, since incident management applies across the full severity range, not only to declared disasters.

After a confirmed compromise of a domain controller, the response team wants to reimage the server immediately to restore service. Litigation is considered likely. The security manager's NEXT action should be to:

  1. Direct that forensic images and volatile data be captured before rebuilding
  2. Approve the reimage because service restoration is the priority
  3. Escalate the decision to the chief executive for a business call
  4. Instruct the team to isolate the server and take no further action pending audit

Answer: A — Direct that forensic images and volatile data be captured before rebuilding

A) Correct — where litigation is reasonably anticipated, preservation obligations attach, and capturing images and memory first costs little while destroying them is irreversible. B) is the technically fastest path and the classic trap; speed here forfeits evidence the organisation will need. C) tempts because major incidents escalate, but the preservation decision sits with the response plan and counsel, not the chief executive. D) freezes the response entirely; isolation plus preservation plus rebuild is the correct sequence, and audit is not the gating function.

Short-term containment differs from long-term containment in that short-term:

  1. Replaces eradication, since the threat goes when the host is isolated
  2. Stops immediate damage while a durable fix is engineered separately
  3. Is the permanent end state once affected systems are segregated
  4. Always requires a full shutdown of the affected business service line

Answer: B — Stops immediate damage while a durable fix is engineered separately

B is the key: two-phase containment buys time without committing to the final architecture. A conflates containment with eradication. C ignores the second phase entirely. D overstates a specific tactic as a rule.

Crisis communication during a significant incident should be:

  1. Ad hoc and decentralized, so each function briefs its own stakeholders
  2. Pre-planned, single-voiced and consistent across all channels used
  3. Limited to social media posts, which reach affected customers fastest
  4. Suspended entirely until the incident has been formally closed

Answer: B — Pre-planned, single-voiced and consistent across all channels used

B is the key: one prepared voice, legally reviewed, protects trust and limits regulatory exposure. A produces contradictory statements. C reaches only one audience and bypasses legal review. D creates a vacuum that others will fill.

During a live intrusion, an engineer identifies the attacker's command-and-control domain and unilaterally blocks it at the perimeter without notifying the incident commander. The plan requires containment actions to be authorised. The security manager's PRIMARY concern is that:

  1. The block may have been technically insufficient to stop the channel
  2. The engineer acted outside the authorisation set by the plan
  3. Perimeter changes require a change advisory board record and approval
  4. The domain may be shared with legitimate business traffic elsewhere

Answer: B — The engineer acted outside the authorisation set by the plan

B) Correct — the governance failure is the bypass of documented authority; an unapproved action can destroy evidence, tip off the adversary, or collide with a wider containment strategy the commander is sequencing. A) is possible but secondary and speculative; effectiveness is assessed after authority is restored. C) tempts because emergency change records matter, but the response plan, not the CAB, governs incident authority. D) is a real operational risk and a good reason for authorisation, yet it is a consequence of the control failure rather than the primary concern itself.

Which of the following BEST demonstrates that incident management training has been effective?

  1. Completion rates for the annual awareness module exceed target
  2. Staff score highly on the post-training knowledge assessment
  3. The number of confirmed incidents declines year on year
  4. Incident reporting rises and escalation time falls

Answer: D — Incident reporting rises and escalation time falls

D) Correct — effectiveness is behavioural: more suspected events reaching the team and reaching it faster is the outcome training is meant to produce. A) measures participation, not capability. B) measures recall immediately after instruction, which correlates poorly with behaviour under stress. C) tempts because fewer incidents sounds like success, but it may equally indicate reduced reporting or weaker detection.

Which condition MOST strongly indicates that an event should be reclassified from a security incident to a crisis requiring executive leadership?

  1. Several critical services and external parties are affected
  2. The incident has persisted for more than twenty-four hours already
  3. The response team has exhausted its first-line containment options
  4. Media enquiries have been received by the corporate press office

Answer: A — Several critical services and external parties are affected

A) Correct — crisis status turns on enterprise-level consequence, particularly simultaneous impact on critical services and external parties, which requires decisions beyond the security function's authority. B) tempts because duration is a common trigger in some plans, but a long low-impact event is not a crisis. C) is an operational escalation to specialist support rather than a crisis declaration. D) is a strong indicator of reputational exposure and often accompanies a crisis, but attention alone is not the criterion.

What is the PRIMARY purpose of an incident response plan?

  1. To create the formal record of incidents after they have been contained and services restored
  2. To define roles, authorities, procedures and communications before an incident occurs
  3. To eliminate the possibility that a security incident will affect the organization's operations
  4. To take the place of the business continuity plan for disruptions arising from any cause
  5. To reassure customers and regulators that the organization takes its security duties seriously

Answer: B — To define roles, authorities, procedures and communications before an incident occurs

B is the point of the plan: decisions about who leads, who may authorize disconnection, whom to notify and on what trigger must be made in advance, because they cannot be made well under pressure. A describes an output of the process, not its purpose. C is unattainable, since no plan prevents incidents. D confuses scope; the response plan handles the security event while continuity keeps the business running. E is a by-product of a credible plan rather than its objective.

Cyber-insurance value during an incident is BEST realized by:

  1. Engaging the insurer and breach coach early and using panel vendors as required
  2. Filing the claim months later once total losses can be stated precisely
  3. Avoiding insurer contact so that renewal premiums are not increased
  4. Following the insurer's marketing material on recommended response steps

Answer: A — Engaging the insurer and breach coach early and using panel vendors as required

A is the key: policies commonly condition coverage on prompt notice and approved vendors. B risks late-notice denial. C forfeits the cover already paid for. D relies on sales material rather than the policy wording.

An organization considers paying a ransomware demand. The PRIMARY governance issue is:

  1. How quickly the payment can be arranged before the stated deadline expires
  2. The wording of the press release that will accompany the decision
  3. Which cryptocurrency exchange or wallet provider should be used
  4. Legal, regulatory and sanctions exposure, needing executive sign-off

Answer: D — Legal, regulatory and sanctions exposure, needing executive sign-off

D is the key: payment can breach sanctions and reporting duties, so it is an executive decision made with counsel and recorded. A treats a governance decision as a logistics problem. B and C are downstream execution details.

Incident Management — Readiness and Response flashcards

4 cards from the 21 in this chapter.

Rank the main incident exercise types by rigour and state what each proves.

Checklist or walkthrough review proves documentation exists and is understood. Tabletop proves decision-making, roles and escalation logic under discussion. Simulation or functional exercise proves that procedures and tools work under time pressure. Full interruption or live test proves actual recovery in production conditions and carries real operational risk.

Why must notification decisions be made by legal and executive management rather than the incident response team?

Notification triggers legal, regulatory and contractual consequences and shapes liability and reputation, so it sits with counsel and executives who hold that accountability. The response team supplies validated facts on scope, data involved and timeline; deciding to notify — or holding a public statement — is not a technical determination.

Containment strategies?

Short-term (isolate quickly) vs long-term (preserve evidence + restore).

What is the difference between an event, an incident and a breach?

An event is any observable occurrence in a system. An incident is an event, or series of events, that actually or imminently jeopardises confidentiality, integrity or availability and requires response. A breach is an incident confirmed to have resulted in unauthorised access to or disclosure of protected data, which is what typically triggers notification obligations.

Practise the full chapter

These are a sample. The full Incident Management — Readiness and Response chapter runs 81 items with per-chapter progress tracking, on the web and in the iOS app.

Open CISM in CoStudy →

Other CISM chapters

All CISM practice questions →