CIM Major Incident Management Procedures 2 — Questions and Answers
Question 1: During a major incident, who is responsible for authorizing emergency changes to production systems?
- The Change Advisory Board (CAB)
- The Emergency Change Advisory Board (ECAB) (Correct answer)
- The Major Incident Manager
- The Service Desk Manager
Correct answer: The Emergency Change Advisory Board (ECAB)
The ECAB is convened to rapidly assess and authorize emergency changes during major incidents without requiring a full CAB meeting.
Question 2: What is the primary purpose of a Post-Incident Review (PIR) following a major incident?
- To assign blame to the team responsible for the outage
- To identify root causes and prevent recurrence (Correct answer)
- To calculate financial penalties from SLA breaches
- To document the incident for regulatory compliance only
Correct answer: To identify root causes and prevent recurrence
The PIR focuses on identifying root causes, contributing factors, and improvement actions to prevent the incident from recurring.
Question 3: Which communication approach is most appropriate when notifying senior stakeholders during an active major incident?
- Provide raw technical logs for full transparency
- Send detailed chronological timelines every 15 minutes
- Deliver concise status updates focused on business impact and ETR (Correct answer)
- Wait until the incident is resolved before communicating
Correct answer: Deliver concise status updates focused on business impact and ETR
Senior stakeholders need concise, business-impact-focused updates with estimated time to restore (ETR) rather than technical details.
Question 4: A major incident is declared at 2:00 AM. The on-call engineer cannot resolve the issue within 30 minutes. What should happen next?
- Allow the engineer more time since it is overnight
- Escalate to the next support tier and invoke the major incident process (Correct answer)
- Wait until business hours to involve additional resources
- Close the incident and reopen it during business hours
Correct answer: Escalate to the next support tier and invoke the major incident process
Time-based escalation triggers ensure the major incident process is activated and additional resources are engaged regardless of time of day.
Question 5: In the context of major incident management, what does 'war room' refer to?
- A secure room where incident evidence is stored
- A centralized physical or virtual space where the response team coordinates (Correct answer)
- A post-incident meeting room for root cause analysis
- A management briefing room separate from the technical team
Correct answer: A centralized physical or virtual space where the response team coordinates
A war room brings key responders together in a single location (physical or virtual) to improve coordination and speed of resolution.
Question 6: Which metric is most useful for measuring the effectiveness of a major incident response team?
- Number of incidents raised per month
- Mean Time to Restore (MTTR) (Correct answer)
- Number of escalations to third-party vendors
- Total number of changes deployed during the incident
Correct answer: Mean Time to Restore (MTTR)
MTTR measures the average time taken to restore normal service, directly reflecting the team's response effectiveness.
Question 7: A major incident affects a business-critical application shared by multiple customer accounts. What is the BEST initial stakeholder notification strategy?
- Notify only the largest customer account first
- Send a single broadcast notification to all affected customers simultaneously (Correct answer)
- Wait for root cause confirmation before notifying any customers
- Escalate internally only and let account managers notify customers individually
Correct answer: Send a single broadcast notification to all affected customers simultaneously
All affected customers should be notified simultaneously with an initial impact statement to maintain transparency and prevent fragmented communication.
During a major incident, who is responsible for authorizing emergency changes to production systems?