CISM - Incident Management (30% of the exam) - Section 4.6

Plan and execute incident management training, testing and evaluation activities including tabletop exercises.

Plan and execute incident management training activities including tabletop exercises, incident simulations, and red team engagements to validate plan effectiveness and build team competency. Use evaluation results from each exercise to identify gaps in the plan or team capability and drive targeted improvements.

Tabletop exerciseRed teamIncident simulationTraining and testing

Practice question for this objective

Free sampleIncident Managementmedium

The board has asked the information security manager to demonstrate that the organisation can actually detect and respond to a realistic, multi-stage attack against production systems, not merely discuss a scenario. Which testing approach is most appropriate to satisfy this request?

  • AA red team engagement that emulates a realistic adversary across multiple stages to test the blue team's detection and response Correct
  • BA tabletop exercise in which executives talk through how they would respond to a hypothetical ransomware outbreak
  • CA vulnerability scan of the production estate with the results presented to the board as evidence of readiness
  • DA configuration audit that compares production system settings against the approved hardening baseline
Use a red team engagement, not a discussion exercise, to demonstrate real detection and response capability against a realistic multi-stage attack. Red teaming emulates a genuine adversary through several attack stages against the live environment, so it exercises the detection technology and the response team under realistic conditions, which a discussion-based or static-assessment approach cannot do.

Why A is correct: A red team safely emulates a multi-stage adversary against production to measure whether monitoring detects the activity and the response team reacts, directly demonstrating real detection and response capability.

Why B is wrong: A tabletop is discussion-based and useful for governance awareness, but it cannot demonstrate genuine detection and response capability against live systems, which is precisely what the board asked to see.

Why C is wrong: A vulnerability scan enumerates weaknesses but does not emulate an attacker or test whether the response team detects and reacts, so it does not demonstrate response capability.

Why D is wrong: A configuration audit confirms systems match a baseline, which is sound preventive hygiene, but it is a static check that tests no detection or response behaviour and so misses the board's request.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Schedule the next exercise at a higher difficulty to see whether the same confusion recurs

    Why it is wrong: Repeating the exercise may eventually surface the issue again, but running another test before analysing this one wastes the lessons already captured and does not drive the corrective change the objective requires.

  • The scenarios that the response team found most engaging and enjoyable in the previous year's exercise

    Why it is wrong: Participant engagement helps attendance and morale, but choosing scenarios for enjoyment ignores actual exposure and would leave the organisation's most likely and damaging incidents untested.

  • It executes the response on live production systems so responders can prove their technical containment tooling works under genuine operating conditions.

    Why it is wrong: Tempting because operational realism sounds rigorous, but this describes a full-scale or functional exercise that touches live systems, which the manager explicitly wanted to avoid here.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.