View Full Isaca CISM Exam Dumps and Practice Test Dumps.
Question 301
What should an incident response plan primarily align with?
- Office layout
- Business needs
- Hiring cycles
- Sales targets
Correct Answer: 2
Explanation
An incident response plan should align with business needs, organizational objectives, risk tolerance, and continuity requirements. Security incidents can affect critical operations, customers, financial performance, legal obligations, and service availability. Therefore, response procedures should reflect which business services are most important and what level of disruption is acceptable. This alignment also helps determine escalation requirements, recovery priorities, and stakeholder involvement. A technically strong response may still create unnecessary business disruption if it ignores organizational requirements. CISM emphasizes connecting security activities with business priorities to ensure incident management effectively supports organizational resilience.
Question 302
Which activity is most useful for determining how an incident occurred?
- Procurement
- Scheduling
- Investigation
- Advertising
Correct Answer: 3
Explanation
Investigation helps determine how an incident occurred, what systems were affected, which activities took place, and what weaknesses contributed to the event. Investigators may review system logs, network information, user activity, configurations, alerts, and other evidence. A structured investigation can establish the incident timeline and help identify the root cause. Evidence should be handled appropriately when it may have legal or regulatory relevance. CISM emphasizes investigation because understanding the cause supports effective containment, eradication, recovery, and corrective action. Simply resolving visible symptoms without investigation may allow similar incidents to occur again.
Question 303
What should influence the size and capability of an incident response team?
- Business risk
- Office size
- Staff age
- Product demand
Correct Answer: 1
Explanation
Business risk should strongly influence incident response staffing and capability requirements. Organizations should consider critical services, threat exposure, incident volume, regulatory obligations, operating hours, and the potential impact of security events. Some organizations may require dedicated responders, while others may use shared internal resources or specialized external providers. Staffing decisions should also consider backup personnel and the skills required for different incident scenarios. CISM emphasizes risk-based resource allocation rather than simply increasing headcount. Management should periodically evaluate whether the available personnel, expertise, technology, and external support are sufficient for the organization’s security and business requirements.
Question 304
Which information should be recorded during incident handling?
- Staff hobbies
- Office colors
- Sales targets
- Key actions
Correct Answer: 4
Explanation
Key actions taken during incident handling should be documented to maintain an accurate record of the response. Important information can include decisions, timestamps, evidence collected, containment measures, communications, escalations, recovery actions, and responsible personnel. Proper documentation helps reconstruct events, support investigations, demonstrate compliance, and provide reliable information during post-incident reviews. It also helps multiple teams coordinate when an incident extends over a long period. CISM emphasizes maintaining appropriate incident records because accurate information supports management decisions and continuous improvement. Organizations should establish documentation requirements before incidents occur and protect records against unauthorized alteration.
Question 305
Which situation may require activation of business continuity procedures?
- Routine scan
- Critical disruption
- Minor alert
- Scheduled update
Correct Answer: 2
Explanation
A critical disruption may require activation of business continuity procedures when normal operations cannot continue within acceptable limits. A major security incident can affect essential services, facilities, systems, personnel, suppliers, or customer-facing operations. Organizations should establish predefined criteria for continuity activation based on business impact, service criticality, recovery objectives, and risk tolerance. Business continuity activities may operate alongside incident response rather than replacing it. CISM emphasizes coordination between security and continuity functions so critical services can continue or recover while the underlying security issue is addressed. This approach reduces operational disruption while supporting an organized recovery process.
Question 306
What should influence the scope of an incident response exercise?
- Business impact
- Staff preference
- Office furniture
- Product color
Correct Answer: 1
Explanation
Business impact should influence the scope of an incident response exercise because exercises should focus on scenarios that could significantly affect organizational objectives. High-impact scenarios may require participation from executives, business owners, technical teams, legal personnel, communications staff, and important third parties. Exercise scope should also reflect threat exposure, critical services, previous incidents, and known weaknesses. CISM promotes risk-based security management, so organizations should avoid exercises that have little relationship to meaningful risks. A well-designed exercise tests whether people, processes, technology, communication channels, and decision-making structures can work together during realistic security events.
Question 307
What should happen when an incident involves sensitive personal information?
- Publish details
- Delete records
- Escalate appropriately
- Ignore exposure
Correct Answer: 3
Explanation
An incident involving sensitive personal information should be escalated according to established security, privacy, legal, and regulatory procedures. Exposure of personal data may create notification obligations, contractual consequences, financial losses, or harm to affected individuals. Responders should preserve relevant evidence, determine the scope of exposure, protect remaining information, and involve appropriate privacy or legal specialists. External communication should only occur through authorized processes and should rely on verified information. CISM emphasizes that security incidents can create business and legal consequences beyond technical systems. Effective management therefore requires coordination among security, business, privacy, legal, and communications stakeholders.
Question 308
Which action is most likely to reduce recurring account compromises?
- Close alerts
- Address root cause
- Reduce monitoring
- Delete logs
Correct Answer: 2
Explanation
Addressing the root cause can reduce recurring account compromises by correcting the weakness that allowed the incidents to occur. Potential causes may include weak authentication, excessive privileges, compromised credentials, insufficient monitoring, poor user awareness, or ineffective access controls. Organizations should analyze evidence before selecting corrective measures so resources are directed toward the actual problem. Closing individual alerts only addresses the immediate event and does not necessarily prevent recurrence. CISM emphasizes continuous improvement and root-cause analysis because recurring incidents may indicate systemic weaknesses. Corrective actions should therefore target underlying causes and be tracked until their effectiveness can be evaluated.
Question 309
Who can provide important information about business impact during an incident?
- Receptionist
- Vendor clerk
- Business owner
- Sales assistant
Correct Answer: 3
Explanation
The business owner can provide important information about the operational impact of an incident because they understand the affected process, service requirements, dependencies, and business consequences. Security personnel may understand the technical scope, but business owners can explain how disruption could affect customers, revenue, regulatory obligations, or critical operations. Their input can help determine severity, recovery priorities, and acceptable downtime. CISM emphasizes collaboration between security and business functions because incident decisions should reflect organizational priorities. Involving appropriate business owners also strengthens accountability and helps ensure that technical response actions support rather than unnecessarily disrupt important business processes.
Question 310
What should guide the sequence for restoring affected services?
- Employee preference
- Device age
- Business priorities
- Office location
Correct Answer: 3
Explanation
Business priorities should guide the sequence for restoring affected services, together with service criticality, dependencies, recovery objectives, and security conditions. When several systems are unavailable, organizations may not be able to restore everything simultaneously. Critical services should therefore receive priority according to predefined business and continuity requirements. Technical dependencies should also be considered because one application may depend on another system or infrastructure component. CISM emphasizes alignment between security and business objectives, so recovery decisions should not be based solely on technical convenience. Business owners and incident leaders should coordinate recovery sequencing to minimize organizational disruption.
Question 311
Why should incident plans document system dependencies?
- Increase sales
- Avoid disruption
- Replace policies
- Reduce staffing
Correct Answer: 2
Explanation
Documenting system dependencies helps responders understand how applications, infrastructure, services, vendors, and business processes interact. This information is important when deciding whether to isolate, shut down, or restore a particular component during an incident. An action affecting a shared system could unintentionally disrupt several critical services if dependencies are unknown. Dependency information also supports recovery sequencing and helps identify important third-party relationships. CISM emphasizes business impact and coordinated response, so incident plans should include relevant technical and operational dependencies. Keeping this information current improves decision-making and reduces the risk of creating additional disruption during containment or recovery.
Question 312
What is a primary purpose of incident escalation procedures?
- Define authority
- Increase sales
- Reduce storage
- Assign uniforms
Correct Answer: 1
Explanation
Incident escalation procedures define when an incident should be transferred to personnel with greater authority, expertise, or responsibility. Procedures may specify severity thresholds, management involvement, decision-making authority, communication requirements, and external notification triggers. Clear escalation rules prevent responders from delaying important decisions because they are uncertain about when to involve senior personnel. Escalation is especially important when incidents affect critical services, sensitive information, or significant business operations. CISM emphasizes governance and accountability, so escalation procedures should be documented, communicated, and tested. Backup contacts should also be identified to ensure escalation remains possible outside normal working hours.
Question 313
Which metric can help identify recurring security incidents?
- Asset price
- Staff count
- Repeat rate
- Office size
Correct Answer: 3
Explanation
Repeat rate can help identify how frequently similar incidents occur after previous events have been addressed. A high recurrence rate may indicate that root causes are not being resolved effectively or that corrective actions are insufficient. Organizations should define what qualifies as a recurring incident and analyze trends by incident type, business impact, and relevant time period. Metrics should be interpreted within context because changes in threat activity can affect incident frequency. CISM emphasizes meaningful security metrics that support management decisions. Recurrence information can help identify persistent weaknesses and determine where additional controls, training, or process improvements may be necessary.
Question 314
What should management do when incident response capacity is inadequate?
- Remove procedures
- Ignore incidents
- Reduce monitoring
- Escalate the gap
Correct Answer: 4
Explanation
When incident response capacity is inadequate, the capability gap should be escalated to management with evidence of the associated business risk. Management may need to provide additional personnel, training, technology, external expertise, or process improvements. The security function should explain how limited capacity could affect detection, response time, containment, recovery, or regulatory requirements. Reducing monitoring or ignoring incidents does not address the underlying risk. CISM emphasizes aligning security resources with organizational requirements and risk exposure. Resource limitations should therefore be presented as management decisions requiring appropriate risk treatment rather than hidden operational problems.
Question 315
Which activity can improve incident coordination with suppliers?
- Reduced monitoring
- Joint exercises
- Fewer contracts
- Informal calls
Correct Answer: 2
Explanation
Joint exercises can improve coordination between an organization and its suppliers by testing communication, escalation, responsibilities, notification requirements, and response procedures. Third parties may operate critical services or process sensitive information, meaning their response capabilities can directly affect organizational resilience. Exercises can reveal outdated contacts, unclear responsibilities, communication delays, or weaknesses in contractual requirements. CISM emphasizes ongoing third-party risk management rather than assessing suppliers only during procurement. Findings from joint exercises should be documented and used to strengthen contracts, procedures, communication channels, and response capabilities. This creates better preparedness for incidents involving important external providers.
Question 316
What should be reviewed when a supplier repeatedly reports incidents late?
- Office design
- Staff uniforms
- Supplier risk
- Product pricing
Correct Answer: 3
Explanation
Supplier risk should be reviewed when a third party repeatedly reports security incidents late. Delayed notification may prevent the organization from taking timely containment actions or meeting regulatory, contractual, or customer notification requirements. Management should determine whether the supplier has adequate incident procedures, whether contractual reporting requirements are sufficiently clear, and whether corrective actions are being implemented. Depending on the level of risk, the organization may require additional assurance, monitoring, remediation, or contractual changes. CISM emphasizes continuous third-party risk management because supplier weaknesses can directly affect organizational security, resilience, compliance, and reputation.
Question 317
Which activity can verify that incident communication channels work?
- Budget review
- Sales meeting
- Office inspection
- Communication test
Correct Answer: 4
Explanation
A communication test can verify whether incident contacts, escalation paths, communication channels, and backup methods work as expected. Testing may reveal outdated contact information, unavailable communication tools, unclear responsibilities, or delays in reaching decision-makers. Communication readiness becomes especially important when normal email, collaboration platforms, or network services are unavailable during an incident. Organizations should periodically test internal and relevant external communication arrangements and update them based on findings. CISM emphasizes preparedness, coordination, and continuous improvement. A communication test provides practical assurance that important stakeholders can exchange accurate information quickly when normal operating conditions are disrupted.
Question 318
What should be confirmed before releasing incident information externally?
- Office size
- Authorization
- Staff preference
- Product demand
Correct Answer: 2
Explanation
Authorization should be confirmed before incident information is released externally because security events may involve confidential information, legal obligations, privacy concerns, contractual restrictions, or incomplete findings. Approved personnel should determine what information can be shared, with whom, and through which communication channels. Depending on the incident, legal, privacy, communications, and senior management functions may need to participate. CISM emphasizes controlled communication because inaccurate or unauthorized statements can create additional organizational consequences. External communication procedures should therefore be established before incidents occur and should identify responsible roles, approval requirements, escalation criteria, and applicable notification obligations.
Question 319
What should a post-incident review produce?
- New office space
- Higher sales
- Improvement actions
- Fewer employees
Correct Answer: 3
Explanation
A post-incident review should produce specific improvement actions that strengthen future security and incident management capabilities. These actions may address root causes, control weaknesses, communication problems, response delays, training deficiencies, or recovery issues. Each action should have an appropriate owner, priority, and tracking method so management can monitor progress. The review should focus on learning and improving processes rather than simply assigning blame. CISM emphasizes continual improvement because organizations should use incident experience to strengthen their capabilities. Effective follow-up ensures that lessons learned become practical changes rather than remaining undocumented observations with no measurable organizational impact.
Question 320
Which practice best supports sustained incident readiness?
- Static plans
- Regular testing
- Limited training
- Fewer exercises
Correct Answer: 2
Explanation
Regular testing supports sustained incident readiness by validating whether plans, people, processes, technology, communication arrangements, and decision-making structures continue to work effectively. Organizations change over time through new systems, personnel, suppliers, regulations, business processes, and emerging threats. Consequently, an incident response plan that worked previously may become outdated. Exercises and simulations help identify weaknesses before a real incident occurs. CISM emphasizes continuous improvement, so testing should be combined with updated procedures, training, lessons learned, and management oversight. Regular validation helps maintain an incident management capability that remains aligned with current organizational risks and operational requirements.