
Certified Information Systems Security Professional
Domain 7Objective 6
7.6 - Conduct Incident Management CISSP Practice Questions (Page 1)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
13%of the exam
Questions 1–5
- 1
What is the first step an incident response team should take after confirming a security incident?
Select an answer first - 2
To whom should incident details be reported when legal or regulatory obligations are triggered?
Select an answer first - 3
After a malware incident, the incident response team has contained the threat and eradicated the malware from the affected systems. The team is now planning to restore the systems to production. What should the team do BEFORE restoring the systems?
Select an answer first - 4
After a security incident, the incident response team is conducting a lessons-learned review. Which of the following is the MOST effective way to capture insights from the review?
Select an answer first - 5
Which activity is part of a post-incident lessons learned review?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.