
Certified Information Security Manager
Domain 4Objective 3
Post-Incident Activity CISM Practice Questions (Page 5)
Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.
30questions here
6free pages
6concepts
30%of the exam
Questions 21–25
- 21
What is the primary purpose of conducting a post-incident review?
Select an answer first - 22
What is the purpose of developing an action plan based on post-incident review findings?
Select an answer first - 23
An organization experienced a service disruption caused by an unpatched vulnerability. During the post-incident review, the team is collecting data to understand the timeline and impact. Which data source is most critical for reconstructing the sequence of events?
Select an answer first - 24
A post-incident review is underway after a data breach. The team has collected logs, emails, and interview notes. However, some logs are missing due to inadequate log retention policies. The security manager must decide how to proceed. What is the most appropriate action?
Select an answer first - 25
Which technique is commonly used to identify the underlying cause of an incident by repeatedly asking 'why'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.