nerdexam
Isaca

CISM · Question #955

Which of the following is the PRIMARY reason to document a security incident?

The correct answer is C. To enable analysis and investigation. Documenting a security incident primarily serves as the foundation for analysis and investigation - without accurate records of what happened, when, and how, you cannot determine root cause, scope of impact, or how to prevent recurrence. Why the distractors fall short: A…

Submitted by rohit_dlh· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the PRIMARY reason to document a security incident?

Options

  • ATo track how many incidents have been reported
  • BTo train and develop incident response staff
  • CTo enable analysis and investigation
  • DTo keep senior leadership informed

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    89% (31)
  • D
    6% (2)

Explanation

Documenting a security incident primarily serves as the foundation for analysis and investigation - without accurate records of what happened, when, and how, you cannot determine root cause, scope of impact, or how to prevent recurrence.

Why the distractors fall short:

  • A (tracking incident counts) is a byproduct of documentation, not its primary purpose - metrics are useful but secondary.
  • B (staff training) may benefit from incident records over time, but that's a downstream use case, not the driving reason to document in the moment.
  • D (informing leadership) is a communication goal; incident reports may be summarized for executives, but documentation exists for technical depth, not executive briefings.

Memory tip: Think of documentation as the "crime scene record" - investigators need it to reconstruct what happened and why, not just to count crimes or brief the police chief. If you can't analyze it, you can't fix it.

Topics

#Incident Documentation#Incident Analysis#Incident Investigation#Incident Response

Community Discussion

No community discussion yet for this question.

Full CISM Practice