Incident Management & Response
48 practice questions with explanations — 15 free to try
PassNova has 48 CISM practice questions on Incident Management & Response, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Incident Management & Response: example questions & answers
3 worked examples with answers and explanations below. Try 15 CISM questions free in the browser; the full 48-question Incident Management & Response bank is part of PassNova Premium.
An information security manager is developing an incident response plan. What should be defined FIRST?
- AThe annual operating budget for the security operations centre
- BThe brand of forensic tools to purchase
- CA clear definition of what constitutes a security incident✓
- DThe marketing message for affected customers
Answer: A clear incident definition is foundational, because it determines what triggers the response process and ensures events are recognised and escalated consistently.
What is the PRIMARY objective of incident response?
- ATo increase the security budget allocated to the function for the following year
- BTo replace all of the affected hardware whether or not it is actually faulty
- CTo identify and assign blame to the individuals who caused the incident
- DTo limit damage and restore normal operations as quickly as possible✓
Answer: The primary objective of incident response is to contain damage and restore normal business operations quickly, minimising overall impact.
During a confirmed active security incident, what should the information security manager prioritise FIRST?
- AUpdating the long-term security strategy
- BIdentifying which employee caused the incident to occur
- CContaining the incident to prevent further damage✓
- DDrafting a press release
Answer: Containment is the immediate priority during an active incident to stop the spread and prevent additional harm before eradication and recovery.