
Information Systems Security Management Professional
Domain 4Objective 3
4.3 Establish and Maintain Incident Management Program ISSMP Practice Questions (Page 7)
Part of the Security Operations domain, which accounts for 18% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
8concepts
18%of the exam
Questions 31–35
- 31
Which incident response methodology is known for its '6-step' process: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned?
Select an answer first - 32
Which of the following is a primary goal of the evidence collection phase in an investigation?
Select an answer first - 33
After a phishing incident that compromised several email accounts, the incident response team needs to report the impact to senior management. The report should help management understand the severity and decide on further investment. What is the most effective way to present the impact?
Select an answer first - 34
A company's incident response team is handling a malware infection on a critical server. The team has contained the infection by isolating the server. The next step is to remove the malware and restore the server to normal operation. Which action should be taken next?
Select an answer first - 35
A security team is establishing a case management process for incident response. The team wants to ensure that each incident has a clear owner, a status, and a record of all actions taken. Which element is most essential for this process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ISSMP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.