
Certified Information Security Manager
Domain 4Objective 3
Post-Incident Activity CISM Practice Questions (Page 6)
Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.
30questions here
6free pages
6concepts
30%of the exam
Questions 26–30
- 26
A security analyst is conducting a post-incident review for a phishing incident that led to credential compromise. The analyst has collected emails, logs, and interview notes. What is the next step in the review process?
Select an answer first - 27
After a post-incident review, the security team has identified several improvement actions. The security manager must decide how to implement them effectively. The team has limited resources and multiple ongoing projects. What is the most effective approach?
Select an answer first - 28
A security manager is planning a post-incident review after a significant security incident. The primary goal of this review is to improve the organization's incident response capability. Which activity is most aligned with this goal?
Select an answer first - 29
Which sequence correctly represents the steps of a post-incident review process?
Select an answer first - 30
What is the primary audience for a post-incident review report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.