Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 4Objective 1

Preparation CISM Practice Questions (Page 5)

Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.

33questions here
7free pages
9concepts
30%of the exam

Questions 21–25

  1. 21application · medium

    During a suspected data breach, an incident responder needs to collect volatile evidence from a compromised server, including running processes and network connections. Which tool is most appropriate for this task?

    Select an answer first
  2. 22foundation · easy

    What is the PRIMARY goal of the containment phase in incident management?

    Select an answer first
  3. 23application · medium

    A regional bank has a single incident response plan that lists the CISO as the sole incident commander for all incidents. During a recent ransomware event, the CISO was unreachable for several hours, and no one else had authority to activate the plan or direct the response. Which improvement should the bank make to its IRP to address this gap?

    Select an answer first
  4. 24foundation · easy

    Which of the following is a key element of an effective incident management training program?

    Select an answer first
  5. 25foundation · easy

    Which of the following is a type of incident response test that involves a discussion-based walkthrough of a scenario?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.