Post-Incident Analysis & Reporting Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Post-Incident Analysis & Reporting flashcards as text
A post-incident report is classified as 'Confidential — Internal Only.' What does this classification most protect?
Answer: Sensitive operational details, security vulnerabilities, and staff privacy from external disclosure
Confidential classification protects sensitive operational and security information from competitors, attackers, and unauthorized parties.
In the context of post-incident reporting, what is 'detection bias' and why is it a concern?
Answer: Preferring certain root cause categories over others during analysis
Detection bias occurs when analysts unconsciously favor familiar root cause categories (e.g., human error) over others, skewing findings and corrective actions.
When a post-incident report identifies a 'single point of failure' (SPOF), what type of corrective action is most appropriate?
Answer: Introducing redundancy, failover, or load balancing to eliminate the SPOF
SPOFs require architectural remediation—redundancy, failover, or load balancing—to prevent a single component failure from causing a full outage.
What is the purpose of tracking 'action item aging' in post-incident management?
Answer: To identify corrective actions that are overdue and escalate them before risks recur
Tracking action item aging ensures overdue corrective actions are escalated and not lost, preventing the same vulnerabilities from persisting indefinitely.
A post-incident analysis reveals the incident was caused by a change deployed without proper testing. Which process improvement would most directly prevent recurrence?
Answer: Strengthening the change management process with mandatory pre-deployment testing gates
Mandatory pre-deployment testing gates in the change management process directly address the failure to validate changes before they reach production.
What is the primary risk of distributing a post-incident report that contains personally identifiable information (PII) of affected customers?
Answer: Regulatory violations (e.g., GDPR, HIPAA) and additional harm to customers whose data is exposed
Including customer PII in reports risks regulatory violations under GDPR, HIPAA, or similar laws and exposes customers to secondary privacy harm.
After publishing a post-incident report, the incident manager should ensure which follow-up activity occurs at regular intervals?
Answer: Reviewing the status of all open corrective actions and updating stakeholders on progress
Regular corrective action status reviews ensure accountability, track progress toward closure, and surface blockers before risks recur.