Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 4Objective 3

Post-Incident Activity CISM Practice Questions (Page 3)

Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.

30questions here
6free pages
6concepts
30%of the exam

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of documenting lessons learned from an incident?

    Select an answer first
  2. 12application · medium

    After a ransomware incident, the incident response team restored systems from backups and resumed operations. During the post-incident review, the team identifies that the initial infection occurred through a phishing email that bypassed the email gateway. The team is now discussing how to prevent recurrence. Which action best aligns with root cause analysis principles?

    Select an answer first
  3. 13application · medium

    Following a post-incident review, the security team has identified several improvement actions, including updating the incident response playbook and deploying additional monitoring. The security manager needs to ensure these actions are actually completed. What is the most effective way to drive implementation?

    Select an answer first
  4. 14foundation · easy

    What is the main goal of root cause analysis in the context of incident management?

    Select an answer first
  5. 15foundation · easy

    During which step of the post-incident review would the team examine logs, system timelines, and interview notes?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.