
Certified Information Security Manager
Domain 4Objective 3
Post-Incident Activity CISM Practice Questions (Page 2)
Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.
30questions here
6free pages
6concepts
30%of the exam
Questions 6–10
- 6
Which component is typically included in a post-incident review report?
Select an answer first - 7
A security manager must present the post-incident review findings to the board of directors. The board is primarily concerned with the financial and reputational impact of the incident. What should the manager emphasize in the presentation?
Select an answer first - 8
A security manager is preparing the post-incident review report for a data breach that affected customer records. The report will be presented to the board of directors and will also be used by the technical team to implement fixes. What is the most effective approach for structuring the report?
Select an answer first - 9
After a malware outbreak, the incident response team documented lessons learned, including the need for better endpoint detection and faster containment procedures. The security manager wants to ensure these lessons translate into tangible improvements. What is the most appropriate next step?
Select an answer first - 10
During a post-incident review, the team discovers that a data breach occurred because a database administrator used a shared service account with a weak password. The team wants to prevent similar incidents. Which action is most directly aligned with root cause analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.