Isaca CISM Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Isaca CISM Exam Dumps and Practice Test Dumps.

 

Question 281

What should trigger incident response activation?

  1. Routine maintenance
  2. Defined criteria
  3. Office changes
  4. Budget approval

Correct Answer: 2

Explanation

Incident response should be activated when predefined criteria indicate that an event requires formal response. These criteria may include confirmed compromise, significant business impact, sensitive information exposure, disruption of critical services, or other conditions established by the organization. Clear activation criteria help personnel distinguish routine events from incidents requiring coordinated action. They also reduce delays caused by uncertainty during an active event. CISM emphasizes preparedness and structured incident management, so organizations should establish activation thresholds before incidents occur. The criteria should be communicated to relevant personnel and reviewed periodically as business risks and threats change.

Question 282

Which activity helps determine incident scope?

  1. Payroll review
  2. Sales analysis
  3. Evidence analysis
  4. Staff scheduling

Correct Answer: 3

Explanation

Evidence analysis helps determine the scope of a security incident by identifying affected systems, accounts, data, applications, network segments, and business processes. Responders can use logs, endpoint information, network activity, authentication records, and other relevant evidence to establish how far the incident has spread. Accurate scope determination is important because incomplete understanding may lead to ineffective containment or premature recovery. CISM emphasizes systematic incident analysis because response decisions should be based on reliable information. Scope should be reassessed as new evidence becomes available, especially when attackers or malicious activity may have affected multiple interconnected environments.

Question 283

Which action best protects evidence integrity?

  1. Controlled handling
  2. Open sharing
  3. Unplanned editing
  4. Public posting

Correct Answer: 1

Explanation

Controlled handling helps protect the integrity of evidence during an investigation. Evidence should be collected, stored, transferred, and accessed according to established procedures, with appropriate documentation and access restrictions. Where legally relevant, organizations may also need to maintain chain-of-custody records showing who handled the evidence and when. Uncontrolled access or unnecessary modification can undermine its reliability and usefulness. CISM incident management should account for evidence preservation requirements before incidents occur. Personnel should understand when specialized forensic or legal support is needed so evidence is handled appropriately throughout the investigation.

Question 284

What is the purpose of an incident severity level?

  1. Track inventory
  2. Guide response
  3. Measure sales
  4. Assign salaries

Correct Answer: 2

Explanation

Incident severity levels help organizations determine the appropriate urgency, resources, escalation, and management involvement for different security events. Severity may consider business impact, affected services, data sensitivity, scope, regulatory implications, and potential consequences. A standardized severity model allows response teams to handle similar incidents consistently and reduces uncertainty during stressful situations. Severity should not be based solely on technical characteristics because business consequences are also important. CISM emphasizes business-oriented incident management, so severity levels should support decisions that protect critical operations and ensure that serious events receive the appropriate level of attention.

Question 285

A response team discovers that an attacker has compromised several accounts. What should be considered first?

  1. Containment
  2. Advertising
  3. Recruitment
  4. Budgeting

Correct Answer: 1

Explanation

Containment should be considered to prevent further unauthorized activity while the organization investigates the compromised accounts. Depending on the circumstances, containment may involve disabling affected accounts, terminating active sessions, resetting credentials, restricting access, or applying additional controls. The selected action should consider business impact and follow established incident procedures. Responders should also preserve relevant evidence before taking actions that could destroy useful information. CISM emphasizes balancing rapid security response with business requirements. Effective containment limits additional damage while providing the response team with an opportunity to investigate the attack and prepare for eradication.

Question 286

Which stakeholder may need incident information for legal assessment?

  1. Marketing
  2. Legal counsel
  3. Reception
  4. Procurement

Correct Answer: 2

Explanation

Legal counsel may need incident information when an event could create legal, regulatory, contractual, privacy, or litigation consequences. Legal specialists can help determine notification requirements, evidence preservation obligations, contractual responsibilities, and restrictions on external communications. Their involvement should follow the organization’s established escalation criteria and should be based on the circumstances of the incident. Not every security event requires legal involvement, but waiting until an incident is closed may prevent timely action when legal deadlines apply. CISM emphasizes predefined escalation procedures so specialized stakeholders can be involved promptly when their expertise is required.

Question 287

What should determine recovery priorities after an incident?

  1. Employee preference
  2. Asset color
  3. Business criticality
  4. Office location

Correct Answer: 3

Explanation

Recovery priorities should be based primarily on business criticality and the importance of affected services to organizational operations. Critical processes may need to be restored before less important services, especially when resources are limited. Organizations should consider business continuity requirements, dependencies, recovery objectives, security conditions, and potential consequences when setting priorities. Restoring systems solely according to technical convenience may leave essential operations unavailable. CISM emphasizes alignment between security management and business objectives, so recovery decisions should reflect the organization’s priorities and risk tolerance while ensuring that systems are secure enough to return to service.

Question 288

Why should incident dependencies be documented?

  1. Support coordination
  2. Increase storage
  3. Reduce staffing
  4. Replace monitoring

Correct Answer: 1

Explanation

Documenting incident dependencies helps response teams understand how systems, applications, services, vendors, and business processes rely on one another. This information is particularly important during containment and recovery because changing one component may affect other critical services. For example, isolating a shared authentication system could disrupt multiple applications. Understanding dependencies allows teams to anticipate consequences and coordinate response actions more effectively. CISM emphasizes business-focused incident management, meaning technical decisions should consider operational relationships. Accurate dependency information also supports recovery planning and helps organizations prioritize restoration of services in a controlled and logical sequence.

Question 289

Which practice improves incident communication accuracy?

  1. Approved reporting
  2. Informal rumors
  3. Public speculation
  4. Unverified messages

Correct Answer: 1

Explanation

Approved reporting procedures improve incident communication accuracy by ensuring that information is reviewed, authorized, and shared through appropriate channels. During a security incident, incomplete or incorrect information can create confusion and lead stakeholders to make poor decisions. Defined reporting responsibilities help ensure that technical facts, business impact, and response status are communicated consistently. Different audiences may require different levels of detail, but all communications should remain accurate and appropriately controlled. CISM emphasizes communication governance because incident information can have operational, legal, regulatory, and reputational implications. Established reporting procedures help reduce unnecessary disclosure and conflicting statements.

Question 290

What should an incident response team do when initial facts are incomplete?

  1. Guess the cause
  2. Preserve evidence
  3. Publish details
  4. Close the case

Correct Answer: 2

Explanation

When initial facts are incomplete, the response team should preserve available evidence while continuing structured investigation and analysis. Early assumptions can be incorrect, particularly during complex incidents where attackers may intentionally create misleading indicators. Preserving logs, system information, and other relevant evidence allows responders to build a more accurate understanding as additional information becomes available. Teams should communicate known facts and clearly identify uncertainty rather than presenting assumptions as confirmed findings. CISM emphasizes evidence-based incident management because premature conclusions can lead to inappropriate containment, communication, recovery, or escalation decisions.

Question 291

Which metric can measure incident detection performance?

  1. Detection time
  2. Office size
  3. Staff count
  4. Asset price

Correct Answer: 1

Explanation

Detection time can help measure how quickly an organization identifies security incidents after they begin or after relevant indicators become available. A shorter detection time may indicate stronger monitoring and analysis capabilities, although the metric should be interpreted according to incident type, complexity, and business context. Organizations may also track mean time to detect across defined incident categories. Metrics should support decisions and improvement rather than simply provide numerical reporting. CISM emphasizes meaningful security measurement, so detection metrics should be linked to incident response objectives and used to identify weaknesses in monitoring, alerting, and analysis processes.

Question 292

What should be done with incident lessons learned?

  1. Ignore them
  2. Archive them only
  3. Apply improvements
  4. Delete them

Correct Answer: 3

Explanation

Lessons learned should be converted into practical improvements rather than simply stored as historical information. Findings may lead to updated procedures, stronger controls, revised playbooks, additional training, improved monitoring, or changes to communication and escalation processes. Each improvement should have appropriate ownership and tracking so management can determine whether corrective actions were completed. CISM emphasizes continuous improvement because every significant incident provides information about the effectiveness of existing security capabilities. Applying lessons learned helps reduce recurring weaknesses and strengthens organizational preparedness. The organization should also validate important changes through testing or subsequent exercises.

Question 293

Which condition can justify declaring a major incident?

  1. Critical service disruption
  2. Routine update
  3. Minor login failure
  4. Scheduled maintenance

Correct Answer: 1

Explanation

A critical service disruption can justify declaring a major incident when it meets the organization’s predefined severity and impact criteria. Major incident declaration may activate additional resources, management involvement, business continuity procedures, specialized technical teams, and formal communication processes. The organization should avoid relying on informal judgment alone because different responders may interpret severity differently. Criteria should consider business impact, scope, urgency, regulatory implications, and affected services. CISM emphasizes predefined incident classification and escalation procedures so major incidents are recognized quickly and managed through an organized structure rather than an improvised response.

Question 294

Which team should coordinate recovery with business owners?

  1. Incident response
  2. Sales
  3. Marketing
  4. Procurement

Correct Answer: 1

Explanation

The incident response team should coordinate recovery activities with relevant business owners and other stakeholders. Technical responders can assess system security and restoration requirements, while business owners understand operational priorities and acceptable service conditions. Effective coordination ensures that recovery decisions consider both security and business needs. For example, a technical team may determine that a system can be restored, while the business owner may identify dependencies or operational requirements that must be addressed first. CISM emphasizes cross-functional coordination because security incidents often affect multiple business areas and recovery decisions should not be made in isolation.

Question 295

Why should incident response plans include alternate communication methods?

  1. Primary systems may fail
  2. Staff may resign
  3. Sales may decline
  4. Offices may expand

Correct Answer: 1

Explanation

Primary communication systems may become unavailable or compromised during a security incident, particularly when the incident affects network infrastructure, identity systems, email, or collaboration platforms. Alternate communication methods allow response teams and management to continue coordinating when normal channels cannot be trusted or accessed. These alternatives should be defined, secured, tested, and available to authorized personnel before an incident occurs. CISM emphasizes preparedness because communication delays can significantly affect incident response. Organizations should periodically verify that alternate channels work as intended and that personnel know when and how to use them during emergencies.

Question 296

What should guide selection of an incident response exercise?

  1. Business risk
  2. Office size
  3. Staff preference
  4. Product demand

Correct Answer: 1

Explanation

Business risk should guide the selection and design of incident response exercises. Organizations should focus testing on scenarios that could materially affect critical operations, sensitive information, regulatory obligations, or important services. Exercise type and complexity can then be selected according to objectives, resources, and organizational maturity. For example, a tabletop exercise may test decision-making, while a technical simulation may assess operational response capabilities. CISM emphasizes risk-based security management, so exercise planning should provide useful assurance about important risks rather than testing random scenarios without a clear purpose.

Question 297

A response plan contains outdated escalation contacts. What is the primary risk?

  1. Delayed response
  2. Higher sales
  3. Lower storage
  4. Better recovery

Correct Answer: 1

Explanation

Outdated escalation contacts can cause delayed response because personnel may be unable to reach individuals responsible for critical decisions, approvals, legal assessment, communications, or business continuity activation. Delays can increase the scope and impact of an incident, particularly when rapid escalation is required. Organizations should periodically review contact information and verify primary and alternate communication paths. Contact lists should also be updated when personnel or organizational structures change. CISM emphasizes readiness and operational continuity, so accurate escalation information is a basic but important requirement for ensuring that incident response procedures function effectively during real events.

Question 298

Which activity helps determine whether response objectives were achieved?

  1. Performance review
  2. Office inspection
  3. Staff survey
  4. Product review

Correct Answer: 1

Explanation

A performance review helps determine whether incident response objectives were achieved and whether the organization’s response capability operated as intended. The review can examine detection speed, escalation, containment, communication, recovery, business impact, and compliance with established procedures. Results should be compared with defined objectives and performance measures rather than relying only on subjective impressions. Significant gaps should lead to corrective actions and appropriate management attention. CISM emphasizes measurable security outcomes because organizations need evidence that incident management capabilities are effective. Performance reviews also provide useful input for improving plans, training, controls, and resource allocation.

Question 299

What should responders do when a third party delays incident notification?

  1. Assess impact
  2. Ignore it
  3. Delete records
  4. Stop monitoring

Correct Answer: 1

Explanation

The organization should assess the impact of the delayed notification and determine whether contractual, regulatory, or internal response requirements were affected. The incident should be managed according to the organization’s established third-party incident procedures, including appropriate escalation and communication with the supplier. The delay itself may also indicate a weakness in the third party’s incident management capability and should be considered during subsequent supplier risk reviews. CISM emphasizes managing third-party risk throughout the relationship, not only during procurement. Significant communication failures should be documented and addressed through appropriate corrective or contractual measures.

Question 300

What is the main purpose of incident response readiness?

  1. Reduce impact
  2. Increase staffing
  3. Remove audits
  4. Expand offices

Correct Answer: 1

Explanation

Incident response readiness ensures that the organization can identify, analyze, contain, communicate, and recover from security incidents with appropriate speed and coordination. Readiness depends on more than having a written plan; it includes trained personnel, defined responsibilities, communication methods, tested procedures, suitable technology, escalation criteria, and coordination with business continuity and recovery capabilities. Regular exercises and reviews help identify weaknesses before a real incident occurs. CISM emphasizes preparedness because effective response reduces disruption and supports organizational resilience. A mature readiness program also uses lessons from incidents and exercises to continuously improve response capabilities.