Isaca CISM Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Isaca CISM Exam Dumps and Practice Test Dumps.

 

Question 201

What is the main purpose of an incident response plan?

  1. Reduce costs
  2. Guide response
  3. Increase staffing
  4. Replace policies

Correct Answer: 2

Explanation

An incident response plan provides structured guidance for handling security incidents. It defines important activities, responsibilities, communication requirements, escalation paths, and response procedures so that personnel can act consistently during stressful situations. The plan should support the organization’s business objectives and align with other relevant plans, including business continuity and disaster recovery. A well-designed plan helps reduce confusion and delays when an incident occurs. It does not replace security policies or eliminate the need for trained personnel. CISM emphasizes organizational preparedness and coordinated response rather than relying on improvised decisions during an incident.

Question 202

Which factor should primarily determine incident severity?

  1. Staff availability
  2. System age
  3. Business impact
  4. Asset cost

Correct Answer: 3

Explanation

Incident severity should primarily reflect the potential or actual business impact of the event. Factors such as affected business processes, sensitive information exposure, service disruption, regulatory consequences, financial losses, and reputational effects can help determine severity. An older system or expensive asset does not automatically make an incident more severe. Similarly, staffing availability should influence response capacity but not define the business severity of an incident. A risk-based severity model helps organizations prioritize incidents consistently and allocate response resources according to their potential consequences and urgency.

Question 203

An incident requires immediate attention because a critical service is unavailable. What should occur first?

  1. Close the ticket
  2. Assess the impact
  3. Rewrite the policy
  4. Replace the system

Correct Answer: 2

Explanation

The incident should first be assessed to determine its scope, impact, affected services, and urgency. This initial assessment supports appropriate prioritization and escalation. When a critical business service becomes unavailable, the response team needs enough information to determine whether the event meets predefined criteria for major incident handling. Immediately replacing systems or rewriting policies would be premature because the organization has not yet established what caused the disruption or what response is required. CISM emphasizes structured incident identification and analysis before selecting containment, recovery, communication, or remediation actions.

Question 204

Which condition most clearly supports incident escalation?

  1. Low impact
  2. Minor delay
  3. High business impact
  4. Routine alert

Correct Answer: 3

Explanation

High business impact is a strong reason to escalate a security incident. Escalation criteria should normally be defined in advance and may include major service disruption, significant data exposure, regulatory implications, widespread compromise, or threats to critical business operations. Escalation ensures that incidents receive the appropriate level of authority, expertise, and resources. A routine alert or minor delay may not require escalation unless additional evidence increases its significance. CISM emphasizes predefined escalation procedures because relying on individual judgment without clear criteria can create inconsistent response decisions and delay management involvement.

Question 205

Why should evidence be preserved during incident response?

  1. Support investigation
  2. Reduce training
  3. Improve sales
  4. Increase storage

Correct Answer: 1

Explanation

Evidence should be preserved to support investigation, determine what occurred, identify affected systems or users, and potentially support legal or disciplinary proceedings. Evidence must be handled carefully so that its integrity and reliability are maintained. Organizations may need procedures for collection, storage, documentation, access control, and chain of custody. Altering or improperly handling evidence can reduce its usefulness during an investigation. CISM expects incident management processes to consider forensic and legal requirements when appropriate. Evidence preservation should therefore be incorporated into incident response procedures rather than treated as an afterthought.

Question 206

What is the primary purpose of chain of custody?

  1. Track evidence
  2. Assign budgets
  3. Rank risks
  4. Approve access

Correct Answer: 1

Explanation

Chain of custody documents the handling and transfer of evidence from the time it is collected until it is ultimately stored, analyzed, presented, or disposed of. It helps demonstrate that evidence has remained controlled and that unauthorized changes or unexplained handling did not occur. This is especially important when an incident may result in legal, regulatory, employment, or law-enforcement proceedings. Proper documentation should identify who handled the evidence, when it was transferred, and where it was stored. CISM incident management should ensure these requirements are understood before evidence collection begins.

Question 207

Who should normally approve external incident communications?

  1. Any analyst
  2. Authorized management
  3. Any employee
  4. Help desk

Correct Answer: 2

Explanation

External communications about security incidents should be handled through authorized personnel and established communication procedures. Depending on the organization, this may involve senior management, legal counsel, public relations, regulatory specialists, or designated incident leaders. Allowing individual analysts or employees to communicate externally can create inconsistent statements, disclose sensitive information, or create legal and regulatory problems. A defined communication process ensures that information is accurate, appropriately authorized, and aligned with organizational obligations. CISM emphasizes clear roles and responsibilities so that incident communications are controlled while still occurring quickly enough to meet business and regulatory needs.

Question 208

When should legal counsel be involved in an incident?

  1. When required
  2. After closure
  3. During training
  4. For every alert

Correct Answer: 1

Explanation

Legal counsel should be involved when an incident may create legal, regulatory, contractual, privacy, or litigation-related consequences. The exact trigger depends on the organization’s policies, jurisdiction, industry requirements, and incident circumstances. Legal involvement can help determine notification obligations, preservation requirements, contractual responsibilities, and appropriate communication. Not every security alert requires legal review, and waiting until an incident is completely closed may be too late. CISM incident management should therefore establish criteria for legal escalation in advance. This allows the organization to involve appropriate specialists promptly when legal considerations become relevant.

Question 209

What should an incident communication plan define?

  1. Contacts
  2. Salaries
  3. Product prices
  4. Office layouts

Correct Answer: 1

Explanation

An incident communication plan should identify who must receive information, who is authorized to communicate, what channels should be used, and when notifications or escalations are required. Important stakeholders may include incident response teams, business owners, executives, legal personnel, regulators, customers, suppliers, or law enforcement, depending on the incident. Clearly defined contacts and communication paths reduce delays and prevent unauthorized disclosure. The plan should also account for communication when normal systems are unavailable. CISM treats communication as a critical incident management activity because poor communication can increase operational, legal, and reputational consequences.

Question 210

What is the main purpose of containment?

  1. Limit damage
  2. Remove evidence
  3. Close reports
  4. Change policies

Correct Answer: 1

Explanation

Containment is intended to limit the spread and impact of a security incident while allowing the organization to continue investigation and response activities. Depending on the incident, containment may involve isolating systems, disabling compromised accounts, blocking malicious connections, or separating affected network segments. The appropriate approach should consider business continuity and the potential consequences of disrupting services. Containment is different from eradication because it focuses on controlling the incident rather than completely removing its root cause. CISM incident management requires organizations to prepare containment strategies appropriate to different incident types and business conditions.

Question 211

Which activity follows effective containment?

  1. Eradication
  2. Budgeting
  3. Hiring
  4. Marketing

Correct Answer: 1

Explanation

After effective containment, the response process can move toward eradication, where the organization removes the underlying cause of the incident. This may include eliminating malware, removing unauthorized accounts, correcting exploited vulnerabilities, or addressing compromised configurations. The exact sequence can vary depending on the incident, but containment generally prevents further damage while investigation and eradication occur. Organizations should avoid declaring an incident resolved simply because visible symptoms have stopped. CISM emphasizes determining whether the threat has actually been removed and whether affected systems can be safely restored without allowing the incident to recur.

Question 212

Why should incident response integrate with business continuity?

  1. Coordinate recovery
  2. Reduce audits
  3. Replace controls
  4. Increase alerts

Correct Answer: 1

Explanation

Incident response and business continuity should work together because serious security incidents can disrupt critical business services. Incident response focuses on identifying, containing, analyzing, and resolving security events, while business continuity focuses on maintaining or restoring essential operations. Integration ensures that security decisions support business recovery and that continuity teams understand security-related conditions that may affect recovery activities. For example, restoring a compromised system before it has been secured could allow an attacker to regain access. CISM therefore emphasizes coordinated planning so that security response and business recovery activities do not conflict.

Question 213

What is the purpose of an incident response exercise?

  1. Test readiness
  2. Approve budgets
  3. Replace audits
  4. Remove controls

Correct Answer: 1

Explanation

An incident response exercise tests whether personnel, processes, communication channels, technologies, and responsibilities are prepared to function during an actual incident. Exercises can reveal unclear roles, outdated contact information, missing procedures, communication problems, or technical dependencies. Tabletop exercises are particularly useful for testing decision-making without disrupting production systems. More technical exercises can evaluate operational response capabilities. The objective is not simply to demonstrate that a plan exists, but to identify weaknesses and improve preparedness. CISM recommends using exercise results to strengthen incident response capabilities and improve organizational readiness over time.

Question 214

A tabletop exercise reveals that nobody knows who can declare a major incident. What should be improved?

  1. Incident roles
  2. Password length
  3. Asset price
  4. Network speed

Correct Answer: 1

Explanation

The organization should clarify incident roles and decision-making authority. Major incident declaration can trigger significant actions, including executive involvement, business continuity activation, external communication, legal review, or emergency resource allocation. If employees are unsure who has authority to declare an incident, response can be delayed or inconsistent. The exercise has therefore identified a governance and process weakness rather than a technical problem. The organization should document declaration criteria, responsible roles, alternates, escalation paths, and communication requirements. Retesting after the improvement can confirm that personnel understand the revised responsibilities.

Question 215

Which metric best measures incident response efficiency?

  1. Office size
  2. Mean response time
  3. Employee age
  4. Server count

Correct Answer: 2

Explanation

Mean response time can help measure how quickly an organization responds to identified security incidents. Depending on the measurement objective, organizations may also track mean time to detect, mean time to contain, mean time to recover, incident volume, recurrence rates, or percentage of incidents handled within defined service targets. Metrics should be aligned with business objectives and interpreted in context rather than viewed in isolation. A shorter response time may indicate improved efficiency, but organizations should also consider incident complexity and severity. Effective CISM metrics provide actionable information for improving incident management capabilities.

Question 216

A supplier reports a breach affecting shared customer data. What should the organization do first?

  1. Ignore it
  2. Assess impact
  3. End all contracts
  4. Publish details

Correct Answer: 2

Explanation

The organization should first assess the incident’s potential impact on its information, customers, operations, legal obligations, and contractual responsibilities. The supplier’s report should be evaluated using established third-party incident response procedures. Depending on the findings, the organization may need to activate internal incident response, preserve evidence, involve legal or privacy teams, notify affected stakeholders, and coordinate remediation with the supplier. Immediately terminating the supplier or publicly disclosing information without assessment could create additional problems. CISM emphasizes coordinated third-party incident management because supplier incidents can directly affect organizational risk and business operations.

Question 217

What should determine regulatory notification timing?

  1. Office policy
  2. Legal requirements
  3. Staff preference
  4. Vendor pricing

Correct Answer: 2

Explanation

Regulatory notification timing should be determined by applicable legal and regulatory requirements, along with relevant contractual obligations and the facts of the incident. Different jurisdictions and regulations can establish different notification thresholds, deadlines, and information requirements. Organizations should therefore have procedures for identifying applicable obligations and involving legal or privacy specialists when necessary. Internal preferences or vendor pricing should not determine whether a mandatory notification is made. CISM incident management should ensure that regulatory requirements are incorporated into response plans so that important deadlines are not missed during a complex security event.

Question 218

Why are incident playbooks useful?

  1. Provide guidance
  2. Replace judgment
  3. Remove testing
  4. Prevent all incidents

Correct Answer: 1

Explanation

Incident playbooks provide practical, scenario-specific guidance for responding to common or high-impact incident types. They can define important actions, responsibilities, decision points, escalation requirements, communication steps, and recovery considerations. Playbooks help responders act consistently and reduce the time needed to determine appropriate actions during an incident. However, they should not eliminate professional judgment because actual incidents may differ from expected scenarios. Playbooks should also be reviewed and tested periodically to remain accurate. CISM emphasizes preparedness, and well-maintained playbooks are one component of an effective incident management capability.

Question 219

What is the main goal of a post-incident review?

  1. Assign blame
  2. Find improvements
  3. Increase spending
  4. Close accounts

Correct Answer: 2

Explanation

A post-incident review should identify lessons learned and opportunities to improve the organization’s ability to prevent, detect, respond to, and recover from future incidents. The review can examine root causes, response effectiveness, communication, escalation, controls, technology, decision-making, and coordination among teams. Its purpose should not be limited to assigning blame because that can discourage honest reporting and reduce organizational learning. Findings should lead to practical improvements, such as process changes, control enhancements, training, updated playbooks, or revised response procedures. CISM emphasizes continuous improvement based on evidence gathered from actual incidents and exercises.

Question 220

What should happen after major incident lessons are identified?

  1. Ignore them
  2. Document actions
  3. Delete records
  4. Stop testing

Correct Answer: 2

Explanation

Lessons identified from a major incident should be documented and converted into specific improvement actions. Each action should have appropriate ownership, priority, and tracking so that identified weaknesses are actually addressed. Improvements may involve changing controls, updating procedures, revising incident playbooks, strengthening training, modifying communication processes, or improving technical capabilities. Simply recording lessons without follow-through does not improve incident readiness. CISM promotes a continual improvement approach in which incident findings are fed back into security and incident management processes. Organizations should also verify that corrective actions have been completed and are effective.