Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 60 discussion

Actual exam question from Isaca's CISM
Question #: 60
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to enhance training for incident response teams?

  • A. Conduct interviews with organizational units.
  • B. Establish incident key performance indicators (KPIs).
  • C. Participate in emergency response activities.
  • D. Perform post-incident reviews.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Jae_kes
Highly Voted 1 year, 5 months ago
Selected Answer: D
D. Perform post-incident reviews. The BEST way to enhance training for incident response teams is to perform post-incident reviews. Post-incident reviews, also known as after-action reviews or lessons learned sessions, involve analyzing and evaluating the response to an incident once it has been resolved. This process allows the incident response team to reflect on their actions, identify strengths and weaknesses, and gather valuable insights for improving their performance in future incidents.
upvoted 7 times
...
AaronS1990
Highly Voted 1 year, 2 months ago
This is very close between C and D. Your answer pretty much comes down to how you interpret the question. Personally I like D as so as ISACA love to emphasise the importance of using post-incident reviews/lessons learned to make improvements.
upvoted 5 times
...
alifjouj
Most Recent 2 months, 3 weeks ago
Selected Answer: D
no better training than real scenarios
upvoted 1 times
...
OlaYiMiKa
3 months, 3 weeks ago
Selected Answer: C
emergency training (similar to fire drills), will help keep every stakeholder alert
upvoted 1 times
...
learntstuff
11 months, 1 week ago
Selected Answer: C
read the question, "enhance training ". D has to do with actual steps in the IR process not training. C deals with training.
upvoted 1 times
...
Cyberbug2021
12 months ago
Selected Answer: D
Real-world learning - not simulated
upvoted 1 times
...
Viperhunter
12 months ago
Selected Answer: D
Performing post-incident reviews, also known as after-action reviews or lessons learned sessions, allows incident response teams to analyze the effectiveness of their response to real incidents. By examining what worked well, identifying areas for improvement, and applying lessons learned, teams can enhance their training and preparedness for future incidents. This iterative process helps teams continually refine their skills and response capabilities. While options like conducting interviews with organizational units (option A), establishing incident key performance indicators (KPIs) (option B), and participating in emergency response activities (option C) are valuable activities, post-incident reviews provide a specific and focused mechanism for learning from real-world experiences and improving incident response training.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
D. While the other options (A, B, and C) can be valuable components of training and preparedness, post-incident reviews play a crucial role in ongoing improvement and are the best way to enhance the effectiveness of incident response teams.
upvoted 2 times
...
Akam
1 year, 3 months ago
For me it's D. Emergency response activities may not be performed very well. Therefore, always post incident reviews will tackle the problems occurred during the response activities and train the response team to not repeat the same mistakes in future activities.
upvoted 2 times
...
rugerfan17
1 year, 5 months ago
Selected Answer: D
D. If you don't know the areas where you're lacking you can't enhance the training, so participating in post evaluation activities will identity areas to train on.
upvoted 4 times
...
richck102
1 year, 6 months ago
C. Participate in emergency response activities.
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: C
Emergency response activities provide a realistic and practical training environment for incident response teams to practice and develop their skills. These activities simulate real-world incidents and allow teams to respond and handle them in a controlled setting. Participating in these activities can help incident response teams to identify any weaknesses or gaps in their response plans and procedures and to improve their response capabilities.
upvoted 1 times
...
CarlPTY07
1 year, 8 months ago
Selected Answer: D
Training is not equal to experience gained. When then participate in response activities they are in the process or gaining experience. When they do lessons learned they improve their knowledge. correct answers is D.
upvoted 4 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: C
Participating in emergency response activities is the best way to enhance training for incident response teams because it provides hands-on, real-world experience in responding to incidents. This type of training allows the team to practice their incident response procedures and develop the necessary skills to effectively respond to incidents. This helps to increase their confidence and competence in the incident response process and can lead to improved performance and a more effective response when a real incident occurs. Additionally, participating in emergency response activities allows the team to identify and address any gaps or weaknesses in their incident response procedures, which can then be corrected before a real incident occurs.
upvoted 1 times
...
STUDYER2
1 year, 9 months ago
Selected Answer: C
Seems putting someone in the response activities would be a better practise then post incident review
upvoted 1 times
...
Antonivs
1 year, 10 months ago
Selected Answer: C
C & D are ok
upvoted 2 times
...
Prospect57
1 year, 10 months ago
Selected Answer: C
C. Is anyone else with me on this one? Post-Incident-Response is *primarily* for improving processes based on what was observed/learned. Identifying *corrective actions* is primary purpose for post incident response. Although I am sure it can help to identify improvements to training, I feel like C is the better option for that.
upvoted 4 times
Sphoz
1 year, 8 months ago
I agree. D is for improvements and lessons learned.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...