CISM - Incident Management - Section 4.6

Plan and execute incident management training, testing and evaluation activities including tabletop exercises.

Plan and execute incident management training activities including tabletop exercises, incident simulations, and red team engagements to validate plan effectiveness and build team competency. Use evaluation results from each exercise to identify gaps in the plan or team capability and drive targeted improvements.

Tabletop exerciseRed teamIncident simulationTraining and testing

Practice question for this objective

Free sampleIncident Managementmedium

The board has asked the information security manager to demonstrate that the organisation can actually detect and respond to a realistic, multi-stage attack against production systems, not merely discuss a scenario. Which testing approach is most appropriate to satisfy this request?

  • AA red team engagement that emulates a realistic adversary across multiple stages to test the blue team's detection and response Correct
  • BA tabletop exercise in which executives talk through how they would respond to a hypothetical ransomware outbreak
  • CA vulnerability scan of the production estate with the results presented to the board as evidence of readiness
  • DA configuration audit that compares production system settings against the approved hardening baseline
Use a red team engagement, not a discussion exercise, to demonstrate real detection and response capability against a realistic multi-stage attack. Red teaming emulates a genuine adversary through several attack stages against the live environment, so it exercises the detection technology and the response team under realistic conditions, which a discussion-based or static-assessment approach cannot do.

Why A is correct: A red team safely emulates a multi-stage adversary against production to measure whether monitoring detects the activity and the response team reacts, directly demonstrating real detection and response capability.

Why B is wrong: A tabletop is discussion-based and useful for governance awareness, but it cannot demonstrate genuine detection and response capability against live systems, which is precisely what the board asked to see.

Why C is wrong: A vulnerability scan enumerates weaknesses but does not emulate an attacker or test whether the response team detects and reacts, so it does not demonstrate response capability.

Why D is wrong: A configuration audit confirms systems match a baseline, which is sound preventive hygiene, but it is a static check that tests no detection or response behaviour and so misses the board's request.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.