CISM · Question #955
Which of the following is the PRIMARY reason to document a security incident?
The correct answer is C. To enable analysis and investigation. Documenting a security incident primarily serves as the foundation for analysis and investigation - without accurate records of what happened, when, and how, you cannot determine root cause, scope of impact, or how to prevent recurrence. Why the distractors fall short: A…
Question
Which of the following is the PRIMARY reason to document a security incident?
Options
- ATo track how many incidents have been reported
- BTo train and develop incident response staff
- CTo enable analysis and investigation
- DTo keep senior leadership informed
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- C89% (31)
- D6% (2)
Explanation
Documenting a security incident primarily serves as the foundation for analysis and investigation - without accurate records of what happened, when, and how, you cannot determine root cause, scope of impact, or how to prevent recurrence.
Why the distractors fall short:
- A (tracking incident counts) is a byproduct of documentation, not its primary purpose - metrics are useful but secondary.
- B (staff training) may benefit from incident records over time, but that's a downstream use case, not the driving reason to document in the moment.
- D (informing leadership) is a communication goal; incident reports may be summarized for executives, but documentation exists for technical depth, not executive briefings.
Memory tip: Think of documentation as the "crime scene record" - investigators need it to reconstruct what happened and why, not just to count crimes or brief the police chief. If you can't analyze it, you can't fix it.
Topics
Community Discussion
No community discussion yet for this question.