CISM Information Security Incident Management 2 — Questions and Answers
Question 1: Which of the following BEST describes 'forensic preservation' during incident response?
- Immediately restoring affected systems to minimize downtime
- Collecting and preserving evidence in a manner that maintains its integrity for investigation (Correct answer)
- Deleting all logs to protect sensitive information
- Notifying law enforcement before any investigation begins
Correct answer: Collecting and preserving evidence in a manner that maintains its integrity for investigation
Forensic preservation involves collecting evidence using documented, integrity-preserving methods to support investigation and potential legal proceedings.
Question 2: A CISM is establishing notification procedures for data breach incidents. Under US regulations, breach notification timing is MOST influenced by:
- The organization's internal investigation timeline
- State breach notification laws and applicable federal regulations (Correct answer)
- The organization's public relations strategy
- The type of security tools used to detect the breach
Correct answer: State breach notification laws and applicable federal regulations
US data breach notification requirements are governed by state laws and federal sector-specific regulations, which define mandatory notification timelines.
Question 3: Which of the following is the MOST important factor in determining incident severity?
- The type of attack technique used by the threat actor
- The potential business impact of the incident (Correct answer)
- The number of systems technically involved
- The time of day the incident was detected
Correct answer: The potential business impact of the incident
Incident severity should be determined by potential business impact — the degree of harm to operations, data, reputation, and stakeholders.
Question 4: During an active ransomware incident, the FIRST priority of the CISM should be to:
- Pay the ransom to restore operations as quickly as possible
- Activate the incident response plan and isolate affected systems (Correct answer)
- Issue a public statement to customers and stakeholders
- Replace all encrypted systems with new hardware
Correct answer: Activate the incident response plan and isolate affected systems
Activating the incident response plan and isolating affected systems are the immediate priorities to contain the ransomware and prevent further spread.
Question 5: Which of the following BEST describes the role of a CISM during a major security incident?
- Personally performing technical forensics on affected systems
- Providing strategic oversight, coordination, and communication (Correct answer)
- Deciding whether to pay a ransom demand
- Writing all incident reports and post-mortem documentation
Correct answer: Providing strategic oversight, coordination, and communication
During a major incident, the CISM's role is strategic — providing oversight, coordinating the response team, and managing communication with leadership.
Question 6: An organization experiences a security incident involving a third-party vendor's system. The CISM should FIRST:
- Immediately terminate the vendor contract
- Invoke the vendor's contractual incident notification and response obligations (Correct answer)
- File a complaint with the vendor's regulatory body
- Deploy monitoring tools on all vendor-connected systems
Correct answer: Invoke the vendor's contractual incident notification and response obligations
Contractual incident notification and response obligations should be invoked immediately to ensure the vendor takes required action and shares necessary information.
Which of the following BEST describes 'forensic preservation' during incident response?