CISM (CISM) General 4 — Questions and Answers
Question 1: Which element is MOST important when developing an information security incident response plan?
- Listing all known threat actors by name
- Defining roles, responsibilities, and escalation procedures (Correct answer)
- Documenting the technical architecture of the SIEM
- Specifying the brand of forensic tools to be used
Correct answer: Defining roles, responsibilities, and escalation procedures
Clear roles, responsibilities, and escalation paths ensure coordinated, timely response when an incident occurs.
Question 2: After containing a security incident, what is the MOST important next step before returning systems to production?
- Notify the press about the incident
- Conduct a root cause analysis and verify eradication of the threat (Correct answer)
- Immediately restore from the most recent backup
- Bill the affected business unit for response costs
Correct answer: Conduct a root cause analysis and verify eradication of the threat
Root cause analysis identifies how the incident occurred and confirms the threat is fully removed, preventing recurrence after restoration.
Question 3: Which type of test evaluates an organization's incident response capabilities WITHOUT disrupting normal operations?
- Full interruption test
- Parallel test
- Tabletop exercise (Correct answer)
- Penetration test
Correct answer: Tabletop exercise
A tabletop exercise walks participants through a simulated scenario in a discussion format, testing plans and decision-making without operational impact.
Question 4: During a ransomware incident, the incident response team is deciding whether to pay the ransom. Who should make this decision?
- The information security manager acting alone
- The IT operations team lead
- Executive management, in consultation with legal and security (Correct answer)
- The threat intelligence vendor
Correct answer: Executive management, in consultation with legal and security
Ransom payment decisions involve legal, financial, reputational, and strategic implications requiring executive authority and legal counsel.
Question 5: The PRIMARY goal of the 'lessons learned' phase of incident response is to:
- Assign blame to responsible employees
- Update insurance claims after the incident
- Identify improvements to prevent or better handle future incidents (Correct answer)
- Finalize forensic evidence for law enforcement
Correct answer: Identify improvements to prevent or better handle future incidents
Lessons learned translate incident experience into actionable improvements in controls, processes, and plans to reduce future risk.
Question 6: An organization experiences a data breach involving personal information. Which regulatory requirement is MOST commonly triggered in the US?
- Mandatory ransom payment disclosure to the IRS
- State data breach notification laws requiring timely consumer notification (Correct answer)
- Mandatory public stock disclosure within 24 hours
- Federal requirement to notify all customers via certified mail
Correct answer: State data breach notification laws requiring timely consumer notification
All 50 US states have breach notification laws requiring organizations to notify affected individuals and sometimes regulators within defined timeframes.
Question 7: Which action BEST preserves digital evidence during an incident investigation?
- Rebooting the affected system to clear malware
- Creating a forensic image of the system before any changes (Correct answer)
- Deleting suspicious files to stop the attack immediately
- Reinstalling the operating system and restoring from backup
Correct answer: Creating a forensic image of the system before any changes
A forensic image captures the exact state of storage at the time of the incident, preserving evidence integrity for analysis or legal proceedings.
Which element is MOST important when developing an information security incident response plan?