Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 4Objective 3

4.3 Establish and Maintain Incident Management Program ISSMP Practice Questions (Page 6)

Part of the Security Operations domain, which accounts for 18% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
8concepts
18%of the exam

Questions 26–30

  1. 26application · medium

    A company experienced a data breach that exposed customer personal information. The incident response team must report the impact to the data protection officer (DPO) and legal counsel. The report should support regulatory notification decisions. Which information is most critical to include?

    Select an answer first
  2. 27expert · hard

    During a forensic investigation, the security team collects a hard drive image from a compromised server. The team needs to analyze the image without altering the original evidence. Which approach is most appropriate?

    Select an answer first
  3. 28expert · hard

    During an investigation of a suspected insider threat, the legal department requests that the investigation be kept confidential. The security team needs to collect evidence from an employee's workstation. The employee is still working and has not been notified. Which action best balances legal requirements and evidence preservation?

    Select an answer first
  4. 29application · medium

    A mid-sized financial firm is establishing an incident response team. The CISO wants to ensure that during a major incident, there is a clear decision-maker, a person who coordinates communication, and technical experts who perform containment. The team will follow NIST SP 800-61. Which structure best meets these requirements?

    Select an answer first
  5. 30application · medium

    A manufacturing company's security team responds to a ransomware incident. During the response, the team lead assigns each responder a specific task, but there is no central record of who performed which action, what was discovered, or when the actions occurred. After containment, the legal department requests a chronological account of all response activities to support potential litigation. Which action best addresses the gap?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.