Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 4Objective 2

Response CISM Practice Questions (Page 4)

Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.

26questions here
6free pages
4concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    An incident response team is investigating a suspected data exfiltration. They have identified a compromised endpoint and need to preserve evidence. Which action is MOST appropriate?

    Select an answer first
  2. 17application · medium

    During an incident investigation, an analyst discovers that a compromised user account was used to access a file share containing sensitive documents. The analyst needs to determine the full scope of the incident. Which action is MOST appropriate?

    Select an answer first
  3. 18expert · hard

    During a major incident, the incident response team needs to communicate with multiple stakeholders, including executives, legal, and technical staff. The team must ensure that information is shared appropriately. What is the MOST important consideration?

    Select an answer first
  4. 19foundation · easy

    During an incident investigation, which activity is most directly associated with determining the root cause of an incident?

    Select an answer first
  5. 20expert · hard

    After a ransomware attack, a company has restored its systems from backups. However, the backups were also encrypted by the ransomware. The company must recover its data. Which action is MOST appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.