nerdexam
Isaca

CISM · Question #812

During which of the following incident management phases would an information security manager MOST likely seek to evaluate the sequence of events leading to a breach and the incident response…

The correct answer is A. Post-incident review phase. The post-incident review phase focuses on analyzing the sequence of events that led to the breach and evaluating the effectiveness of the incident response activities, with the goal of identifying lessons learned and improving future incident handling.

Submitted by viktor_hu· Apr 18, 2026Information Security Incident Management

Question

During which of the following incident management phases would an information security manager MOST likely seek to evaluate the sequence of events leading to a breach and the incident response activities that were initiated?

Options

  • APost-incident review phase
  • BIncident containment phase
  • CIncident response phase
  • DIncident identification phase

How the community answered

(39 responses)
  • A
    87% (34)
  • B
    5% (2)
  • D
    8% (3)

Explanation

The post-incident review phase focuses on analyzing the sequence of events that led to the breach and evaluating the effectiveness of the incident response activities, with the goal of identifying lessons learned and improving future incident handling.

Topics

#Incident Management Phases#Post-Incident Review#Lessons Learned#Incident Evaluation

Community Discussion

No community discussion yet for this question.

Full CISM Practice