View Full Isaca CISM Exam Dumps and Practice Test Dumps.
Question 221
Which activity helps confirm that an incident was detected correctly?
- Validation
- Budgeting
- Hiring
- Marketing
Correct Answer: 1
Explanation
Incident validation confirms that an alert represents a genuine security event rather than a false positive or routine activity. Analysts should review available evidence, determine what occurred, identify affected assets, and establish whether the event meets the organization’s incident criteria. Accurate validation is important because unnecessary escalation can waste resources, while failure to recognize a real incident can increase business impact. CISM incident management emphasizes structured detection and analysis so that response resources are directed toward events that require action. Validation should therefore occur before major response activities are initiated whenever circumstances allow.
Question 222
What is the main purpose of incident categorization?
- Track costs
- Classify events
- Assign salaries
- Replace controls
Correct Answer: 2
Explanation
Incident categorization classifies security events according to predefined types or characteristics, such as malware, unauthorized access, data exposure, service disruption, or policy violation. Consistent categorization helps organizations route incidents to appropriate personnel, apply suitable response procedures, identify trends, and produce meaningful management reports. Categories should be understandable and aligned with the organization’s incident management process. Categorization does not determine every response decision by itself; severity, business impact, and urgency must also be considered. CISM encourages structured incident management because consistent classification improves coordination and supports effective analysis of incident patterns.
Question 223
Which factor is most important when prioritizing incidents?
- Business impact
- Device color
- Office size
- Employee tenure
Correct Answer: 1
Explanation
Business impact is a key factor when determining incident priority. An event affecting a critical business process may require immediate attention even if the number of affected systems is relatively small. Organizations should consider factors such as service disruption, sensitive information exposure, regulatory obligations, financial consequences, and potential harm to customers or operations. Priority criteria should be defined before incidents occur so response teams can make consistent decisions. CISM focuses on aligning incident management with business needs, ensuring that limited response resources are directed toward incidents that could cause the greatest organizational consequences.
Question 224
When should an incident be formally declared?
- When criteria are met
- After all recovery
- During every alert
- Only after audit
Correct Answer: 1
Explanation
An incident should be formally declared when predefined criteria indicate that an event has reached the organization’s threshold for incident response. These criteria may include confirmed compromise, significant business impact, sensitive information exposure, regulatory implications, or disruption of critical services. Formal declaration activates appropriate roles, procedures, escalation paths, and communication processes. Waiting until recovery is complete defeats the purpose of incident declaration, while declaring every minor alert an incident can overwhelm response resources. CISM recommends establishing clear declaration criteria in advance so that personnel understand when an event requires coordinated organizational response.
Question 225
A critical system is compromised. What should the response team consider before isolation?
- Business impact
- Office design
- Staff age
- Product demand
Correct Answer: 1
Explanation
Before isolating a critical system, the response team should consider the potential business impact of the action. Isolation may prevent further compromise, but it can also interrupt essential services, affect customers, or interfere with other recovery activities. The decision should balance containment needs against operational requirements and should follow predefined response procedures where possible. Teams may need to consult business owners or incident leaders before taking disruptive actions. CISM emphasizes that incident response must remain aligned with business priorities, meaning technical containment decisions should consider both security consequences and the organization’s ability to continue critical operations.
Question 226
What is the purpose of an incident severity matrix?
- Guide priority
- Reduce storage
- Approve vendors
- Assign payroll
Correct Answer: 1
Explanation
An incident severity matrix provides a consistent method for evaluating incidents based on factors such as business impact, scope, affected information, urgency, and regulatory significance. It helps response teams determine how quickly an incident should be handled and what level of management involvement may be required. A well-designed matrix reduces inconsistent decisions between analysts and supports appropriate allocation of response resources. Severity criteria should be understandable, documented, and periodically reviewed. CISM emphasizes repeatable incident management processes because clearly defined severity levels help organizations respond proportionately to different types of security events.
Question 227
Why should incident roles be assigned before an incident occurs?
- Reduce confusion
- Increase alerts
- Replace training
- Remove policies
Correct Answer: 1
Explanation
Incident roles should be established before an incident occurs so personnel understand their responsibilities during a potentially stressful and time-sensitive event. Defined roles can include incident manager, technical responders, communications personnel, legal representatives, business owners, and recovery coordinators. Clear responsibilities reduce duplication, delays, and conflicting decisions. Organizations should also identify alternates to maintain coverage when primary personnel are unavailable. CISM emphasizes preparedness because assigning responsibilities during an active crisis can create uncertainty. Regular exercises should verify that personnel understand their roles and that escalation and communication responsibilities are practical.
Question 228
Which activity best supports incident readiness?
- Regular exercises
- Fewer policies
- Delayed testing
- Manual billing
Correct Answer: 1
Explanation
Regular exercises are an important component of incident readiness because they allow organizations to test plans, roles, communication procedures, technical capabilities, and decision-making before a real incident occurs. Exercises can expose weaknesses that may not be visible during routine operations. Organizations can use tabletop discussions, simulations, or technical exercises depending on their objectives and risk profile. Findings should be documented and followed by corrective actions. CISM emphasizes preparedness rather than assuming that written plans are sufficient. An incident response capability becomes more reliable when personnel have repeatedly practiced the procedures they may need to use.
Question 229
What should an incident response plan include for unavailable personnel?
- Alternate roles
- Product prices
- Office maps
- Sales targets
Correct Answer: 1
Explanation
An incident response plan should identify alternate personnel and backup responsibilities for critical incident roles. Security incidents can occur outside normal working hours, during vacations, or when primary responders are unavailable. Without defined alternates, important decisions may be delayed because employees do not know who has authority to act. The plan should include escalation contacts, backup responsibilities, communication methods, and procedures for activating additional resources when necessary. CISM emphasizes operational readiness, meaning incident response should not depend entirely on individual employees. Role redundancy and clear succession arrangements help maintain response capability during prolonged or unexpected incidents.
Question 230
Which communication method is best during a major incident?
- Approved channel
- Public forum
- Personal blog
- Unverified chat
Correct Answer: 1
Explanation
Major incidents should use communication channels that have been approved and established for incident response. These channels should support appropriate confidentiality, availability, authentication, and accountability. Public forums, personal blogs, or unverified communication platforms may expose sensitive information or create confusion about official organizational statements. Organizations should also prepare alternate communication methods in case normal systems are unavailable or compromised. CISM incident management requires communication procedures that define who can communicate, what information can be shared, and which channels should be used. Controlled communication helps maintain accurate information flow while reducing unnecessary disclosure.
Question 231
What should responders do when evidence may be legally relevant?
- Preserve it
- Delete it
- Modify it
- Ignore it
Correct Answer: 1
Explanation
Potentially legally relevant evidence should be preserved according to established forensic and legal procedures. This includes protecting evidence integrity, documenting its collection and handling, restricting unauthorized access, and maintaining appropriate chain-of-custody records. Responders should avoid actions that could unintentionally alter or destroy evidence. Legal or forensic specialists may need to provide guidance depending on the circumstances and jurisdiction. CISM incident management should account for these requirements in advance rather than expecting technical responders to make legal decisions independently. Proper evidence preservation helps support investigations and protects the organization if later legal or regulatory action occurs.
Question 232
Which activity helps determine whether an incident has spread?
- Scope analysis
- Budget review
- Staff survey
- Policy drafting
Correct Answer: 1
Explanation
Scope analysis determines how broadly an incident has affected the organization. Responders may examine compromised accounts, systems, applications, network segments, data repositories, and business processes to establish the extent of the event. Understanding scope is essential for effective containment because isolating only one affected component may leave other compromised areas accessible to an attacker. Scope analysis should continue as new evidence becomes available because initial findings may be incomplete. CISM incident management emphasizes accurate analysis before declaring an incident contained or resolved, helping ensure that response actions address the full extent of the security event.
Question 233
Why should incident records be maintained?
- Support analysis
- Increase sales
- Reduce staffing
- Replace audits
Correct Answer: 1
Explanation
Incident records provide a documented history of events, decisions, actions, communications, and outcomes. They support investigation, management reporting, regulatory requirements, trend analysis, lessons learned, and future incident response improvements. Accurate records can also help establish timelines and demonstrate that appropriate procedures were followed. Records should be protected from unauthorized modification and retained according to organizational, legal, and regulatory requirements. CISM emphasizes that incident documentation is not merely administrative. It provides evidence that can help the organization understand recurring weaknesses, measure response performance, and improve security controls and incident management processes.
Question 234
What should incident metrics primarily support?
- Decisions
- Decoration
- Advertising
- Payroll
Correct Answer: 1
Explanation
Incident metrics should provide information that supports management and operational decisions. Useful metrics can include detection time, response time, containment time, recovery time, incident volume, recurrence rates, severity distribution, and performance against defined service objectives. Metrics should be selected based on organizational goals rather than simply reporting numbers that are easy to collect. Management needs information that demonstrates whether incident capabilities are improving and whether significant risks remain. CISM emphasizes actionable measurement, meaning incident metrics should help identify weaknesses, allocate resources, prioritize improvements, and communicate security performance in terms that stakeholders can understand.
Question 235
A response team detects repeated incidents from the same vulnerability. What is the best action?
- Address the root cause
- Close each alert
- Ignore recurrence
- Reduce monitoring
Correct Answer: 1
Explanation
Repeated incidents caused by the same vulnerability indicate that addressing individual events alone is insufficient. The organization should investigate and address the underlying root cause, which may involve a missing patch, ineffective configuration, weak process, inadequate control, or insufficient monitoring. Corrective action should be prioritized according to business risk and may require cooperation among security, technology, and business teams. Simply closing each alert allows the underlying weakness to remain and can result in repeated disruption. CISM emphasizes lessons learned and continuous improvement so that incident management reduces recurrence rather than repeatedly treating symptoms.
Question 236
What is the main purpose of incident recovery?
- Restore operations
- Assign blame
- Increase alerts
- Replace policies
Correct Answer: 1
Explanation
Incident recovery aims to restore affected systems and business services to a secure and acceptable operating condition. Recovery should occur only after appropriate containment, eradication, validation, and authorization activities have been completed. Depending on the incident, recovery may involve restoring backups, rebuilding systems, validating security controls, monitoring restored services, and obtaining business owner approval. Organizations should avoid rushing systems back into production if the underlying threat remains. CISM emphasizes coordinated recovery because security and business continuity objectives must both be considered. Recovery activities should also generate lessons that can improve future preparedness and resilience.
Question 237
Who should approve return of a critical business service?
- Authorized owner
- Any analyst
- Any employee
- External user
Correct Answer: 1
Explanation
The authorized business or service owner should normally approve the return of a critical service, in coordination with incident response and technical teams. The owner understands the operational importance of the service and can determine whether business requirements for restoration have been met. Technical personnel should verify that security conditions and recovery procedures are satisfactory, but they may not have authority to make the final business decision. Defined approval responsibilities prevent premature restoration and clarify accountability. CISM emphasizes coordinated decision-making between security, technology, and business stakeholders throughout incident recovery.
Question 238
What should be verified before restoring a compromised system?
- Security status
- Office seating
- Staff uniforms
- Product demand
Correct Answer: 1
Explanation
Before restoring a compromised system, the organization should verify that the underlying threat has been removed or adequately controlled and that the system is in a secure state. This may include validating patches, configurations, malware removal, access controls, monitoring, and system integrity. Restoring a system without confirming its security status can allow attackers or malicious software to regain access. Recovery should therefore include appropriate testing and authorization before returning the system to normal operation. CISM incident management emphasizes controlled recovery because restoring availability without addressing security weaknesses can cause repeated incidents.
Question 239
Which action improves incident response after a failed exercise?
- Correct weaknesses
- Ignore findings
- Stop testing
- Remove procedures
Correct Answer: 1
Explanation
Weaknesses identified during an exercise should be analyzed and corrected through specific improvement actions. For example, the organization may need to update contact lists, clarify escalation authority, revise procedures, improve technical capabilities, or provide additional training. Findings should be assigned to responsible owners and tracked until completion. Another exercise can then verify whether the changes improved readiness. Ignoring findings wastes the value of the exercise and leaves the organization exposed to the same problems during a real incident. CISM promotes continual improvement, using testing and exercises as opportunities to strengthen incident management capabilities.
Question 240
What is the primary objective of incident management?
- Minimize impact
- Increase spending
- Eliminate audits
- Reduce staffing
Correct Answer: 1
Explanation
The primary objective of incident management is to minimize the business impact of security incidents and restore normal operations in a controlled manner. Effective incident management includes preparation, detection, analysis, prioritization, containment, eradication, recovery, communication, and post-incident improvement. The goal is not simply to resolve technical problems but to protect business objectives while managing security events effectively. Organizations should establish appropriate roles, procedures, communication paths, and escalation criteria before incidents occur. CISM emphasizes a business-focused approach in which incident management supports resilience, reduces disruption, and improves the organization’s ability to handle future events.