CIM Post-Incident Analysis & Reporting 4 — Questions and Answers
Question 1: An incident report includes an 'impact statement.' What should this section quantify?
- The number of responders who worked on the incident
- The business, financial, customer, and reputational effects of the incident (Correct answer)
- The technical root cause in detail
- The tools and monitoring systems that were used
Correct answer: The business, financial, customer, and reputational effects of the incident
The impact statement quantifies business harm—affected users, revenue loss, SLA breaches, regulatory exposure—to prioritize remediation investments.
Question 2: What is the difference between a 'post-incident review' (PIR) and a 'problem record' in ITIL-aligned incident management?
- A PIR is a meeting/report analyzing a specific incident; a problem record tracks the underlying root cause for longer-term resolution (Correct answer)
- PIR and problem record are the same document
- A problem record is only created for security incidents
- A PIR is mandatory; problem records are optional
Correct answer: A PIR is a meeting/report analyzing a specific incident; a problem record tracks the underlying root cause for longer-term resolution
A PIR reviews the specific incident response, while a problem record is a longer-lived ITIL artifact tracking root cause investigation and fix progress.
Question 3: Which section of a post-incident report is typically read by executives who want to understand impact and next steps without technical detail?
- Root cause analysis appendix
- Executive summary (Correct answer)
- Technical timeline
- Alert log attachment
Correct answer: Executive summary
The executive summary provides a concise overview of the incident, business impact, and key remediation commitments in non-technical language.
Question 4: During a post-incident analysis, a responder reveals they deviated from the runbook because 'it didn't match the actual system state.' What is the best follow-up action?
- Discipline the responder for not following procedure
- Update the runbook to reflect reality and investigate why it became out of date (Correct answer)
- Archive the runbook and create a new one from scratch
- Require runbook sign-off by all responders monthly
Correct answer: Update the runbook to reflect reality and investigate why it became out of date
Runbook drift indicates a documentation maintenance failure; the correct action is updating the runbook and establishing a review cadence.
Question 5: What does 'SMART' stand for when defining corrective actions in a post-incident report?
- Specific, Measurable, Achievable, Relevant, Time-bound (Correct answer)
- Systematic, Managed, Auditable, Repeatable, Tested
- Scalable, Monitored, Automated, Resilient, Traced
- Structured, Measurable, Aligned, Risk-based, Trackable
Correct answer: Specific, Measurable, Achievable, Relevant, Time-bound
SMART criteria ensure corrective actions are Specific, Measurable, Achievable, Relevant, and Time-bound so they can be tracked and verified.
Question 6: Which participant is typically responsible for facilitating a post-incident review meeting to ensure it remains blameless and productive?
- The most senior engineer on-call during the incident
- A neutral facilitator, often the incident manager or a designated SRE (Correct answer)
- The department head who oversees the affected service
- A legal representative to assess liability
Correct answer: A neutral facilitator, often the incident manager or a designated SRE
A neutral facilitator—typically the incident manager or an SRE—guides the PIR discussion to keep it focused, blameless, and outcome-oriented.
Question 7: When calculating MTTR in a post-incident report, the clock stops when which condition is met?
- The root cause is identified
- Service is fully restored to normal operation for all affected users (Correct answer)
- The incident bridge call ends
- The post-incident report is published
Correct answer: Service is fully restored to normal operation for all affected users
MTTR (Mean Time to Repair/Restore) ends when the service is fully restored to normal operation, not when diagnosis or documentation is complete.
An incident report includes an 'impact statement.' What should this section quantify?