Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 4Objective 2

Response CISM Practice Questions (Page 5)

Part of the Domain 4: Incident Management domain, which accounts for 30% of the CISM exam.

26questions here
6free pages
4concepts
30%of the exam

Questions 21–25

  1. 21application · medium

    During an incident, the incident response team discovers that a third-party vendor has access to the affected system. The team needs to communicate with the vendor. What is the MOST important consideration?

    Select an answer first
  2. 22expert · hard

    A company's critical application server is infected with malware that is actively spreading. The server cannot be taken offline without causing significant business disruption. The incident response team must contain the threat while maintaining availability. Which approach is MOST appropriate?

    Select an answer first
  3. 23foundation · easy

    Which stakeholder group must be notified when an incident involves personally identifiable information (PII) and is subject to data protection regulations?

    Select an answer first
  4. 24foundation · easy

    Which containment strategy is most appropriate when an infected system must remain online for forensic evidence collection, but its communication with other systems must be restricted?

    Select an answer first
  5. 25application · medium

    An organization experiences a security incident that may involve personally identifiable information (PII). The incident response team is unsure whether the breach meets the threshold for regulatory notification. Who should make the final determination?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.