Free Certified Information Security Manager practice — 6 questions on Incident Management, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 4: Incident Management
A financial institution's incident response plan defines an RPO of 1 hour for its core transaction database. Current backups are taken every 4 hours via snapshot replication. During a security incident, the database is corrupted and must be restored from the last valid backup. Which of the following BEST addresses the gap between the defined RPO and the actual backup capability?
RPO is derived from the business impact analysis and represents the maximum tolerable data loss determined by business requirements. When actual capability falls short, the correct response is to invest in technical capability (more frequent backups or continuous replication) to close the gap, not to arbitrarily lower the business requirement.
Question 2 of 6 · Domain 4: Incident Management
An organization's incident classification matrix assigns severity levels based on business impact. During triage, a security analyst discovers that a phishing email compromised a single non-privileged user's mailbox, with no evidence of lateral movement, privilege escalation, or data exfiltration. According to typical incident severity criteria used in mature incident management programs, this incident should be classified as:
A single-account compromise with no evidence of spread, privilege escalation, or data loss represents limited business impact and is typically classified as low to moderate severity, handled through routine incident handling procedures with standard reporting.
Question 3 of 6 · Domain 4: Incident Management
Following eradication and recovery from a ransomware incident, the incident response team drafts a report. Management asks the security manager to ensure the post-incident review produces actionable value. Which of the following should be the PRIMARY focus of the post-incident review?
The primary purpose of a post-incident review from a management perspective is continuous improvement: identifying root causes and control gaps, and driving corrective actions that reduce the likelihood and impact of future incidents.
Question 4 of 6 · Domain 4: Incident Management
An organization discovers that a data breach affecting the personal data of EU customers occurred 50 hours ago and was confirmed as a reportable breach 10 hours ago. Per the regulatory notification procedures referenced in the incident response plan under GDPR, which action is MOST appropriate for the incident manager to take now?
GDPR requires notification to the relevant supervisory authority within 72 hours of becoming aware of a reportable breach; the clock started at confirmation. Phased or preliminary notification with a commitment to follow-up detail is expected and compliant when full facts are not yet available.
Question 5 of 6 · Domain 4: Incident Management
In a well-designed incident management program, who should have the authority to formally declare an incident and activate the incident response plan?
Formal incident declaration should be governed by a predefined role and documented criteria (e.g., incident manager or CISO) to ensure consistent, appropriately scaled activation of response resources based on severity thresholds.
Question 6 of 6 · Domain 4: Incident Management
A security manager is reviewing the organization's incident management plan and business continuity plan for alignment. During a recent incident simulation, it was determined that the current disaster recovery site (a cold site) cannot meet the maximum tolerable downtime (MTD) defined by the business impact analysis for the organization's critical payment processing system. Which of the following actions should the security manager recommend?
When existing DR infrastructure cannot meet a business-derived MTD, the appropriate response is to invest in a recovery strategy (warm or hot site) capable of achieving the required recovery timeframe, aligning capability with the defined business requirement.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.