CISM

Incident Management & Response

48 practice questions with explanations — 15 free to try

PassNova has 48 CISM practice questions on Incident Management & Response, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Incident Management & Response: example questions & answers

3 worked examples with answers and explanations below. Try 15 CISM questions free in the browser; the full 48-question Incident Management & Response bank is part of PassNova Premium.

  1. An information security manager is developing an incident response plan. What should be defined FIRST?

    • AThe annual operating budget for the security operations centre
    • BThe brand of forensic tools to purchase
    • CA clear definition of what constitutes a security incident
    • DThe marketing message for affected customers

    Answer: A clear incident definition is foundational, because it determines what triggers the response process and ensures events are recognised and escalated consistently.

  2. What is the PRIMARY objective of incident response?

    • ATo increase the security budget allocated to the function for the following year
    • BTo replace all of the affected hardware whether or not it is actually faulty
    • CTo identify and assign blame to the individuals who caused the incident
    • DTo limit damage and restore normal operations as quickly as possible

    Answer: The primary objective of incident response is to contain damage and restore normal business operations quickly, minimising overall impact.

  3. During a confirmed active security incident, what should the information security manager prioritise FIRST?

    • AUpdating the long-term security strategy
    • BIdentifying which employee caused the incident to occur
    • CContaining the incident to prevent further damage
    • DDrafting a press release

    Answer: Containment is the immediate priority during an active incident to stop the spread and prevent additional harm before eradication and recovery.

Start practising Incident Management & Response →