CIM Post-Incident Analysis & Reporting 5 — Questions and Answers
Question 1: A post-incident report is classified as 'Confidential — Internal Only.' What does this classification most protect?
- The organization from legal discovery in litigation
- Sensitive operational details, security vulnerabilities, and staff privacy from external disclosure (Correct answer)
- The incident manager's reputation
- Customer data referenced in the report
Correct answer: Sensitive operational details, security vulnerabilities, and staff privacy from external disclosure
Confidential classification protects sensitive operational and security information from competitors, attackers, and unauthorized parties.
Question 2: In the context of post-incident reporting, what is 'detection bias' and why is it a concern?
- Over-relying on automated alerts and ignoring manual detection methods in the analysis
- Focusing the analysis only on events that were detectable, ignoring near-misses that weren't caught
- Preferring certain root cause categories over others during analysis (Correct answer)
- The tendency to report more incidents than actually occurred
Correct answer: Preferring certain root cause categories over others during analysis
Detection bias occurs when analysts unconsciously favor familiar root cause categories (e.g., human error) over others, skewing findings and corrective actions.
Question 3: When a post-incident report identifies a 'single point of failure' (SPOF), what type of corrective action is most appropriate?
- Increasing monitoring alert thresholds
- Introducing redundancy, failover, or load balancing to eliminate the SPOF (Correct answer)
- Documenting the SPOF in the runbook and accepting the risk
- Assigning a dedicated operator to monitor the SPOF continuously
Correct answer: Introducing redundancy, failover, or load balancing to eliminate the SPOF
SPOFs require architectural remediation—redundancy, failover, or load balancing—to prevent a single component failure from causing a full outage.
Question 4: What is the purpose of tracking 'action item aging' in post-incident management?
- To measure how old the incident management team is
- To identify corrective actions that are overdue and escalate them before risks recur (Correct answer)
- To archive completed actions after 90 days
- To calculate SLA breach age for billing purposes
Correct answer: To identify corrective actions that are overdue and escalate them before risks recur
Tracking action item aging ensures overdue corrective actions are escalated and not lost, preventing the same vulnerabilities from persisting indefinitely.
Question 5: A post-incident analysis reveals the incident was caused by a change deployed without proper testing. Which process improvement would most directly prevent recurrence?
- Hiring more on-call engineers
- Strengthening the change management process with mandatory pre-deployment testing gates (Correct answer)
- Increasing monitoring coverage after deployments
- Reducing the deployment frequency
Correct answer: Strengthening the change management process with mandatory pre-deployment testing gates
Mandatory pre-deployment testing gates in the change management process directly address the failure to validate changes before they reach production.
Question 6: What is the primary risk of distributing a post-incident report that contains personally identifiable information (PII) of affected customers?
- The report will be too long to read effectively
- Regulatory violations (e.g., GDPR, HIPAA) and additional harm to customers whose data is exposed (Correct answer)
- It will delay the corrective action implementation
- Customers will demand refunds
Correct answer: Regulatory violations (e.g., GDPR, HIPAA) and additional harm to customers whose data is exposed
Including customer PII in reports risks regulatory violations under GDPR, HIPAA, or similar laws and exposes customers to secondary privacy harm.
Question 7: After publishing a post-incident report, the incident manager should ensure which follow-up activity occurs at regular intervals?
- Re-interviewing all responders quarterly
- Reviewing the status of all open corrective actions and updating stakeholders on progress (Correct answer)
- Republishing the report with updated timestamps
- Conducting a new incident simulation based on the report
Correct answer: Reviewing the status of all open corrective actions and updating stakeholders on progress
Regular corrective action status reviews ensure accountability, track progress toward closure, and surface blockers before risks recur.
A post-incident report is classified as 'Confidential — Internal Only.' What does this classification most protect?