CISM Information Security Incident Management 1 — Questions and Answers
Question 1: What is the FIRST step in the incident response lifecycle according to best practices?
- Containment
- Eradication
- Preparation (Correct answer)
- Recovery
Correct answer: Preparation
Preparation is the first phase of incident response, involving developing plans, training teams, and establishing capabilities before incidents occur.
Question 2: During a security incident, who is PRIMARILY responsible for declaring an incident a 'major incident'?
- The system administrator who detected the anomaly
- A designated incident manager or crisis management team (Correct answer)
- The external auditor assigned to the organization
- The help desk technician who received the initial report
Correct answer: A designated incident manager or crisis management team
A designated incident manager or crisis management team, with appropriate authority, is responsible for formally declaring and escalating major incidents.
Question 3: Which of the following is the PRIMARY purpose of containment in incident response?
- To permanently remove the root cause of the incident
- To limit the scope and impact of an ongoing incident (Correct answer)
- To restore affected systems to normal operation
- To document lessons learned from the incident
Correct answer: To limit the scope and impact of an ongoing incident
Containment limits the spread and impact of an active incident while preserving evidence and buying time for eradication and recovery.
Question 4: A CISM is reviewing an incident response plan (IRP). Which element is MOST critical to include?
- A list of all security software licenses
- Defined escalation procedures and communication chains (Correct answer)
- Detailed technical specifications for all security tools
- Annual training completion records for all staff
Correct answer: Defined escalation procedures and communication chains
Clearly defined escalation procedures and communication chains ensure that the right people are notified and empowered to act during an incident.
Question 5: After an incident is resolved, which activity is MOST important to improve future response?
- Immediately patching all systems in the environment
- Conducting a post-incident review (lessons learned) (Correct answer)
- Resetting all user passwords organization-wide
- Replacing all affected hardware immediately
Correct answer: Conducting a post-incident review (lessons learned)
A post-incident review (lessons learned) identifies what worked, what failed, and improvements to prevent recurrence and enhance future response capability.
Question 6: Which of the following BEST describes the purpose of an incident response retainer with a third-party firm?
- To outsource all internal security operations permanently
- To ensure pre-negotiated access to expert resources during a crisis (Correct answer)
- To replace the need for an internal incident response plan
- To satisfy cyber insurance policy requirements only
Correct answer: To ensure pre-negotiated access to expert resources during a crisis
A retainer pre-negotiates access to specialized incident response expertise and resources, reducing response time and ensuring availability during a major incident.
What is the FIRST step in the incident response lifecycle according to best practices?