CIM Incident Response Planning & Coordination 5 — Questions and Answers
Question 1: An Incident Manager is asked to evaluate whether an incident response plan is 'fit for purpose.' Which test BEST validates this?
- Reviewing the plan document for completeness against a checklist
- Conducting a full-scale simulation exercise that mirrors likely real-world scenarios (Correct answer)
- Obtaining sign-off from all department heads
- Comparing the plan to a competitor organization's published IRP
Correct answer: Conducting a full-scale simulation exercise that mirrors likely real-world scenarios
Simulation exercises expose gaps in procedures, tools, and human response that document reviews alone cannot reveal.
Question 2: During incident coordination, the Incident Manager learns that a resolver group lacks access to a critical system needed for diagnosis. What should the Incident Manager do?
- Wait for the normal access request process to complete
- Invoke the emergency access provisioning procedure defined in the IRP to grant temporary access (Correct answer)
- Assign a different team that already has access, even if they lack expertise
- Escalate to the CISO to determine if access should be granted
Correct answer: Invoke the emergency access provisioning procedure defined in the IRP to grant temporary access
IRPs should include emergency access provisioning procedures that override standard request workflows to avoid resolution delays during critical incidents.
Question 3: What is the MAIN difference between an Incident Response Plan and a Business Continuity Plan (BCP)?
- An IRP focuses on IT systems only, while a BCP covers all business operations
- An IRP targets restoring normal IT service operations, while a BCP ensures business functions continue during prolonged disruptions (Correct answer)
- A BCP is tested annually; an IRP is never formally tested
- An IRP is owned by IT; a BCP is owned by legal and compliance
Correct answer: An IRP targets restoring normal IT service operations, while a BCP ensures business functions continue during prolonged disruptions
IRPs address rapid service restoration within IT operations, while BCPs provide broader organizational continuity strategies for extended disruptions beyond IT's scope.
Question 4: A Certified Incident Manager is onboarding a new responder to the major incident team. Which competency is MOST important to develop first?
- Advanced scripting and automation skills
- Understanding of the IRP structure, escalation paths, and their specific role responsibilities (Correct answer)
- Ability to perform root cause analysis independently
- Proficiency in all monitoring tools used by the organization
Correct answer: Understanding of the IRP structure, escalation paths, and their specific role responsibilities
Role clarity and plan familiarity ensure the new responder can act correctly within the coordinated response structure before developing specialized technical skills.
Question 5: An organization has separate incident response plans for each IT domain (network, application, database). What is the PRIMARY coordination risk of this approach?
- Plans will have conflicting SLA targets for the same incident
- Cross-domain incidents may fall into gaps where no single plan owns overall coordination (Correct answer)
- The plans will be too long and difficult to read during an incident
- Each domain will require a separate war room
Correct answer: Cross-domain incidents may fall into gaps where no single plan owns overall coordination
Domain-siloed plans lack a master coordination layer, so multi-domain incidents — the most complex and common major incidents — have no clear overall owner or unified process.
Question 6: Which activity should occur IMMEDIATELY after service restoration in a major incident, before the incident is officially closed?
- Root cause analysis and permanent fix implementation
- Confirmation from business stakeholders that service is restored to acceptable levels (Correct answer)
- Archiving all incident tickets and communication logs
- Updating the service catalog with new downtime figures
Correct answer: Confirmation from business stakeholders that service is restored to acceptable levels
Business stakeholder confirmation validates that restoration meets user requirements, not just that technical indicators are green, before the incident can be officially closed.
Question 7: A post-incident review finds that the Incident Manager failed to update stakeholders for 90 minutes during a P1 incident. Which IRP component would have MOST directly prevented this?
- A severity classification matrix with clearer P1 definitions
- Defined communication cadence requirements specifying maximum intervals between stakeholder updates (Correct answer)
- An automated monitoring dashboard accessible to stakeholders
- A pre-incident stakeholder training program on incident management
Correct answer: Defined communication cadence requirements specifying maximum intervals between stakeholder updates
Mandatory update cadences (e.g., every 20-30 minutes for P1) create accountability and prevent communication gaps regardless of incident complexity.
An Incident Manager is asked to evaluate whether an incident response plan is 'fit for purpose.' Which test BEST validates this?