Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 4Objective 3

Post-Incident Activity CISM Practice Questions (Page 1)

Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.

30questions here
6free pages
6concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A post-incident review has been completed, and the security manager must communicate the findings to various stakeholders, including the executive team, the IT department, and external regulators. What is the most important consideration when preparing the report?

    Select an answer first
  2. 2foundation · easy

    Which element is essential for lessons learned documentation to be actionable?

    Select an answer first
  3. 3expert · hard

    After a post-incident review, the security team has developed a list of improvement actions, including patching critical vulnerabilities, updating the incident response plan, and conducting additional staff training. The security manager has limited budget and must prioritize the actions. Which action should be prioritized first?

    Select an answer first
  4. 4application · medium

    After a post-incident review, the security team identified that the incident response plan lacked clear escalation procedures, which delayed containment. The team has drafted an updated plan. What is the most effective way to ensure the updated plan is effective?

    Select an answer first
  5. 5application · medium

    During a post-incident review, the team identifies that a lack of network segmentation allowed malware to spread rapidly. The team documents this as a lesson learned. What is the most important characteristic of this lesson learned documentation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.