Step2Study
IT & Technology100% Free

Certified Information Security Manager (CISM)

Practice bank
286 Qs
Real exam
150 Qs
Time limit
240 min
Passing
A scaled score of 450 or higher

Exam blueprint

Information Security Governance
24%
Information Security Risk Management
30%
Information Security Program
27%
Incident Management
19%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 150 questions each · 240 min · pass 75% · 286 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Certified Information Security Manager (CISM) practice test questions

Sample questions from the 286-question bank, with answers and explanations.

All questions
  1. 1. A CISO is tasked with implementing a new incident response playbooks system. The goal is to ensure that playbooks are actionable, consistent, and easily updated, allowing the incident response team (IRT) to respond effectively to a wide range of incidents. Which of the following approaches is MOST effective for designing and maintaining these playbooks?

    Incident Management

    • A. Creating modular playbooks based on incident types, with adaptable response steps and decision points.
    • B. Developing highly detailed, prescriptive playbooks for every known threat scenario.
    • C. Entrusting senior IR analysts to maintain playbooks independently based on their experience.
    • D. Utilizing a commercial incident response platform that provides pre-built, static playbooks.
    Show answer

    A. Creating modular playbooks based on incident types, with adaptable response steps and decision points.

    Creating modular playbooks based on incident types, with adaptable response steps and decision points, provides the optimal balance. It standardizes common actions while allowing flexibility for unique incident characteristics, making them actionable, consistent, and easier to update than highly prescriptive documents.

  2. 2. An organization is developing its information security program. The information security manager is tasked with ensuring that the program aligns with business objectives. Which of the following actions is MOST crucial to achieve this alignment?

    Information Security Risk Management

    • A. Engage with business unit leaders to understand their objectives and risk tolerance.
    • B. Implement a robust security awareness training program for all employees.
    • C. Conduct a comprehensive technical vulnerability assessment of all systems.
    • D. Benchmark the program against industry best practices and standards.
    Show answer

    A. Engage with business unit leaders to understand their objectives and risk tolerance.

    Aligning the information security program with business objectives requires understanding what those objectives are and the associated business risks. Engaging directly with business unit leaders provides this crucial insight, ensuring security efforts support, rather than hinder, business goals and are tailored to the organization's specific risk tolerance.

  3. 3. An organization is considering deploying a new cloud-based application that will process highly sensitive customer data. The information security manager is conducting a risk assessment and identifies that the cloud provider's data encryption at rest uses a key management system (KMS) where the encryption keys are managed solely by the provider. Which of the following risk responses is MOST appropriate in this scenario?

    Information Security Risk Management

    • A. Transfer the risk by purchasing cyber insurance.
    • B. Remediate the risk by requiring the cloud provider to implement customer-managed keys (CMK).
    • C. Avoid the risk by not deploying the application to the cloud.
    • D. Accept the risk, as encryption is being used by the cloud provider.
    Show answer

    B. Remediate the risk by requiring the cloud provider to implement customer-managed keys (CMK).

    For highly sensitive data, relying solely on a cloud provider's managed encryption keys presents a potential risk of unauthorized access (e.g., via subpoena to the provider or insider threat). Requiring customer-managed keys (CMK) allows the organization to retain full control over the encryption keys, thus remediating a significant portion of this risk by ensuring only the organization can decrypt the data.

  4. 4. A CISO is developing an information security program for a newly established FinTech startup. The startup operates in a highly regulated industry and aims for rapid growth. Which of the following should be the CISO's PRIMARY focus when initially structuring the program?

    Information Security Risk Management

    • A. Implementing advanced threat intelligence feeds and security analytics platforms.
    • B. Hiring a large team of security analysts to manage 24/7 security operations.
    • C. Establishing a strong governance framework aligned with business objectives and regulatory requirements.
    • D. Deploying a comprehensive suite of endpoint detection and response (EDR) tools.
    Show answer

    C. Establishing a strong governance framework aligned with business objectives and regulatory requirements.

    For a startup in a highly regulated industry, establishing a strong governance framework is paramount. This framework will ensure that the security program is aligned with business objectives, meets regulatory obligations from the outset, and provides the foundation for all subsequent security initiatives, rather than jumping straight to specific technical controls or operational staffing.

  5. 5. A healthcare organization is developing its Disaster Recovery Plan (DRP). The CISO is debating the inclusion of a comprehensive communication plan with external stakeholders (e.g., regulators, media, patients). What is the MOST compelling reason to integrate such a communication plan into the DRP?

    Incident Management

    • A. It reduces the overall cost of disaster recovery operations.
    • B. It minimizes the impact on system availability during recovery.
    • C. It streamlines internal decision-making during a disaster.
    • D. It ensures compliance with legal and regulatory reporting requirements.
    Show answer

    D. It ensures compliance with legal and regulatory reporting requirements.

    For healthcare organizations, legal and regulatory requirements (like HIPAA) often mandate specific timelines and methods for notifying affected individuals, regulators, and sometimes the media in the event of a data breach or system outage affecting patient data. A comprehensive external communication plan ensures these obligations are met, mitigating legal and reputational risks.

  6. 6. A Chief Information Security Officer (CISO) is presenting the information security program's progress and effectiveness to the board of directors. The board is primarily interested in understanding the financial impact of security investments and how they contribute to the organization's bottom line. Which metric would be MOST effective for the CISO to use to demonstrate the financial value of security initiatives?

    Information Security Risk Management

    • A. Number of vulnerabilities identified and remediated per quarter.
    • B. Return on Investment (ROI) for security projects, adjusted for risk.
    • C. Compliance adherence rates with regulatory requirements.
    • D. Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for incidents.
    Show answer

    B. Return on Investment (ROI) for security projects, adjusted for risk.

    The board of directors is typically focused on financial performance and strategic value. Risk-adjusted ROI for security projects directly translates security investments into financial terms, showing how they either save money (by preventing losses) or enable business growth, which is highly relevant to board-level discussions.

  7. 7. An organization is conducting a disaster recovery (DR) exercise. The scenario involves the complete loss of its primary data center. During the exercise, it is discovered that while individual applications can be restored, the interdependencies between critical business applications are not correctly accounted for, leading to functional failures and extended recovery times. Which of the following actions should the CISO prioritize to address this deficiency?

    Incident Management

    • A. Conducting a comprehensive inter-application dependency mapping initiative.
    • B. Increasing the frequency of DR exercises to identify more issues.
    • C. Implementing a more robust backup solution for individual applications.
    • D. Investing in a geographically separate hot site for immediate failover.
    Show answer

    A. Conducting a comprehensive inter-application dependency mapping initiative.

    The core problem is the lack of understanding of inter-application dependencies. A comprehensive mapping initiative would identify these relationships, allowing for a more coordinated and effective recovery sequence, directly addressing the root cause of the functional failures.

  8. 8. A CISO is developing a business continuity plan (BCP) for a critical business process that relies heavily on specialized personnel. The CISO recognizes that the sudden unavailability of these key individuals could severely impact the organization's ability to recover. Which of the following actions is MOST effective in mitigating this human factor risk?

    Incident Management

    • A. Developing detailed, step-by-step Standard Operating Procedures (SOPs) for all critical tasks.
    • B. Establishing a formal succession plan for all senior management and technical experts.
    • C. Purchasing key-personnel insurance policies for all specialized staff members.
    • D. Implementing a comprehensive cross-training program for critical roles within the organization.
    Show answer

    D. Implementing a comprehensive cross-training program for critical roles within the organization.

    Cross-training critical roles ensures that multiple individuals possess the necessary skills to perform essential functions, directly mitigating the risk associated with the unavailability of specialized personnel and enhancing the organization's resilience.

  9. 9. A CISO is reviewing the organization's business continuity plan (BCP) and identifies a critical dependency on a single third-party vendor for a key communication platform. A disruption to this vendor could severely impact the organization's ability to communicate with customers and employees during a crisis. Which of the following is the MOST effective strategy to mitigate this single point of failure within the BCP?

    Incident Management

    • A. Implement service level agreements (SLAs) with the vendor for high availability and quick recovery.
    • B. Develop an alternative communication strategy and relationship with a secondary vendor.
    • C. Require the vendor to provide their own BCP document for review.
    • D. Conduct annual penetration tests on the vendor's communication platform.
    Show answer

    B. Develop an alternative communication strategy and relationship with a secondary vendor.

    To mitigate a single point of failure, especially for a critical dependency, establishing an alternative strategy with a secondary vendor provides true resilience. While SLAs and vendor BCPs offer assurance, they don't eliminate the risk of a single vendor failing entirely; a secondary option ensures continuity.

  10. 10. A CISO is establishing an incident response program for a mid-sized financial institution. The CISO wants to ensure that the program can adapt to emerging threats and technologies while maintaining core principles. Which of the following components is MOST crucial for achieving this adaptability?

    Incident Management

    • A. A well-defined incident response policy that outlines roles, responsibilities, and guiding principles.
    • B. Investing in a Security Orchestration, Automation, and Response (SOAR) platform.
    • C. Detailed, step-by-step incident response playbooks for every conceivable scenario.
    • D. Regularly scheduled, unannounced incident response drills and tabletop exercises.
    Show answer

    A. A well-defined incident response policy that outlines roles, responsibilities, and guiding principles.

    A well-defined incident response policy provides the foundational framework and guiding principles that allow an incident response program to adapt. Playbooks can become outdated, SOAR is a tool, and exercises test readiness, but the policy defines the overarching strategy.

  11. 11. A company's CISO is reviewing the Business Continuity Plan (BCP) and discovers that several critical business functions lack a defined Recovery Point Objective (RPO). What is the MOST significant risk associated with an undefined RPO for a critical business function?

    Incident Management

    • A. Increased cost of recovery infrastructure and services.
    • B. Inability to determine the maximum tolerable downtime (MTD).
    • C. Potential for excessive data loss during a recovery event.
    • D. Failure to identify the necessary recovery time objective (RTO).
    Show answer

    C. Potential for excessive data loss during a recovery event.

    The RPO defines the maximum acceptable amount of data loss measured in time (e.g., 1 hour of data loss). If an RPO is undefined, there is no clear target for how much data can be lost, leading to a high risk of recovering an outdated state and thus excessive data loss that impacts business operations significantly.

  12. 12. A CISO is reviewing the organization's incident response metrics. The metrics currently track the total time from incident detection to full resolution. To improve the effectiveness of the detection phase and identify potential weaknesses in monitoring systems, which of the following metrics should the CISO additionally prioritize?

    Incident Management

    • A. Mean Time To Recover (MTTR)
    • B. Mean Time To Detect (MTTD)
    • C. Mean Time Between Failures (MTBF)
    • D. Mean Time To Contain (MTTC)
    Show answer

    B. Mean Time To Detect (MTTD)

    Mean Time To Detect (MTTD) specifically measures the average time it takes to identify an incident from its inception. Prioritizing this metric directly addresses the effectiveness of the detection phase and helps pinpoint weaknesses in monitoring systems and early warning capabilities.

  13. 13. A new Chief Information Security Officer (CISO) is establishing an information security program for a rapidly growing startup. The CISO recognizes the need to align security investments with business objectives. What is the MOST crucial initial step in developing an effective information security program?

    Information Security Risk Management

    • A. Perform a business impact analysis (BIA) to identify critical assets and processes.
    • B. Implement security awareness training for all employees.
    • C. Conduct a comprehensive technical vulnerability assessment.
    • D. Develop a detailed incident response plan.
    Show answer

    A. Perform a business impact analysis (BIA) to identify critical assets and processes.

    A BIA identifies an organization's critical business functions, processes, and the assets that support them, along with the impact of their disruption. This foundational understanding is essential for aligning security investments with actual business needs and prioritizing protection.

  14. 14. A large e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that disrupts its online sales for several hours. The incident response team successfully mitigates the attack, but the CISO is asked to quantify the total impact. Beyond direct revenue loss and mitigation costs, which of the following 'intangible' costs is MOST challenging to accurately quantify but can have a profound long-term impact?

    Incident Management

    • A. Cost of replacing compromised hardware and software licenses.
    • B. Regulatory fines and legal fees associated with non-compliance.
    • C. Loss of intellectual property due to data exfiltration.
    • D. Increased customer churn and damage to brand reputation.
    Show answer

    D. Increased customer churn and damage to brand reputation.

    Loss of brand reputation and customer churn are notoriously difficult to quantify accurately because their impact unfolds over time and can be influenced by many factors. While they are intangible, their long-term effect on future revenue and market share can be profound.

  15. 15. A CISO is reviewing the organization's disaster recovery plan (DRP) and identifies that while technical recovery procedures are well-documented, there is no clear process for managing the transition of business operations back to the primary site after a disaster. Which of the following is the MOST significant risk uncovered by this finding?

    Incident Management

    • A. Increased Recovery Time Objective (RTO) for critical systems.
    • B. Extended business disruption due to inefficient or uncoordinated restoration of normal operations.
    • C. Failure to meet regulatory compliance requirements for data retention.
    • D. Potential for data loss during the failback process.
    Show answer

    B. Extended business disruption due to inefficient or uncoordinated restoration of normal operations.

    Without a clear process for transitioning back to the primary site (failback or restoration), the organization faces significant risks of extended disruption. This includes potential for re-introducing vulnerabilities, operational confusion, and prolonged business downtime, even if technical systems are recovered.

  16. 16. A global enterprise with diverse business units is developing its incident response strategy. The CISO is evaluating models to balance centralized control with local responsiveness. Which incident response model is BEST suited for an organization that requires a strong central oversight but also empowers local teams to handle routine incidents independently?

    Incident Management

    • A. Federated model
    • B. Distributed model
    • C. Centralized model
    • D. Outsourced model
    Show answer

    A. Federated model

    A federated incident response model balances centralized control with local autonomy. It allows local teams to handle routine incidents within their scope while providing central oversight, shared resources, and escalation paths for major or complex incidents, fitting the requirement for both central oversight and local responsiveness.

  17. 17. A CISO is establishing a new incident response program for a mid-sized financial institution. The CISO wants to ensure that the program can effectively address various types of incidents while maintaining operational efficiency. Which of the following is the MOST critical first step in developing a robust incident response capability?

    Incident Management

    • A. Developing an incident response policy and clearly defining roles and responsibilities.
    • B. Hiring a dedicated 24/7 Security Operations Center (SOC) team.
    • C. Procuring advanced Security Information and Event Management (SIEM) solutions.
    • D. Conducting regular penetration testing and vulnerability assessments.
    Show answer

    A. Developing an incident response policy and clearly defining roles and responsibilities.

    Establishing a foundational incident response policy is the most critical first step. It provides the necessary framework, defines the program's scope, and assigns responsibilities, which are essential before investing in technology or personnel.

  18. 18. During a review of an organization's vulnerability management program, the CISO notes that while many vulnerabilities are identified, the mean time to remediate (MTTR) critical findings is consistently high. Which of the following actions should the CISO prioritize to improve this situation?

    Information Security Risk Management

    • A. Increase the frequency of vulnerability scans.
    • B. Implement a robust patch management process with clear ownership.
    • C. Expand the scope of vulnerability assessments to include web applications.
    • D. Invest in an advanced threat intelligence platform.
    Show answer

    B. Implement a robust patch management process with clear ownership.

    A high Mean Time To Remediate (MTTR) indicates a bottleneck in the remediation phase, not the identification phase. A robust patch management process with clear ownership directly addresses the ability to fix vulnerabilities in a timely manner.

  19. 19. A CISO is developing a disaster recovery plan (DRP) for an organization that relies heavily on a critical legacy application. This application has highly specialized hardware requirements and is incompatible with modern virtualization platforms and cloud environments. The organization has a limited budget for DR, making a hot site financially unfeasible. Which of the following recovery strategies is MOST appropriate for this specific legacy application?

    Incident Management

    • A. Utilizing a warm site with partially configured legacy hardware.
    • B. Migrating the application to a modern cloud-native architecture.
    • C. Implementing a cold site with specialized hardware pre-positioned.
    • D. Negotiating a reciprocal agreement with another organization for hardware.
    Show answer

    C. Implementing a cold site with specialized hardware pre-positioned.

    Given the 'highly specialized hardware requirements', 'incompatible with modern platforms', and 'limited budget', a cold site with pre-positioned specialized hardware is the most appropriate and cost-effective strategy. While recovery time will be longer, it addresses the unique hardware needs within budget constraints.

  20. 20. A CISO is establishing a new incident response team. To ensure the team can effectively manage incidents of varying severity and complexity, from minor alerts to major breaches, which organizational structure design principle is MOST critical?

    Incident Management

    • A. Implementing a rigid hierarchical structure with clearly defined command chains.
    • B. Outsourcing the entire incident response function to a third-party managed security service provider (MSSP).
    • C. Establishing a flat organizational structure to promote rapid decision-making.
    • D. Designing a scalable and flexible structure that can adapt to incident scope.
    Show answer

    D. Designing a scalable and flexible structure that can adapt to incident scope.

    The ability to scale and flex the incident response structure is crucial for handling incidents of varying severity and complexity. This means having a core team that can expand with additional resources and specialized roles as needed, ensuring appropriate response without over-committing resources to minor incidents or being overwhelmed by major ones.

  21. 21. An organization relies on a critical legacy system that processes sensitive data but lacks modern security features and cannot be easily patched. Replacing the system is prohibitively expensive and time-consuming. Which of the following risk treatment strategies is MOST appropriate for the CISO to recommend in this situation?

    Information Security Risk Management

    • A. Risk Avoidance, by completely discontinuing the use of the legacy system.
    • B. Risk Transfer, by purchasing a comprehensive cybersecurity insurance policy.
    • C. Risk Acceptance, by formally acknowledging the risk without further action.
    • D. Risk Mitigation, by implementing compensating controls around the legacy system.
    Show answer

    D. Risk Mitigation, by implementing compensating controls around the legacy system.

    Given that replacing the system (avoidance) is too expensive and accepting the risk without action is irresponsible for sensitive data, the most appropriate strategy is risk mitigation. This involves implementing compensating controls (e.g., network segmentation, strict access controls, intrusion detection) around the legacy system to reduce its exposure and impact, thereby mitigating the risk without direct modification to the system itself.

  22. 22. A CISO is establishing an incident response team for a medium-sized enterprise. Which of the following roles is MOST critical to ensure effective coordination and decision-making during a major security incident?

    Incident Management

    • A. Public Relations Specialist
    • B. Forensic Analyst
    • C. Legal Counsel
    • D. Incident Commander
    Show answer

    D. Incident Commander

    The Incident Commander is responsible for overall management of the incident, including strategy, objectives, and resource allocation, making it the most critical role for effective coordination and decision-making.

  23. 23. A CISO is reviewing the organization's current incident response plan. The plan details steps for technical containment and eradication but lacks specific guidance on preserving potential evidence for legal or forensic purposes. What is the MOST significant risk posed by this oversight?

    Incident Management

    • A. Inability to prosecute attackers or recover damages.
    • B. Increased Recovery Time Objective (RTO) for affected systems.
    • C. Diminished ability to detect future similar attacks.
    • D. Higher financial costs for incident response tools.
    Show answer

    A. Inability to prosecute attackers or recover damages.

    Without proper evidence preservation, the organization significantly loses its ability to pursue legal action against attackers, support insurance claims, or comply with regulatory reporting requirements, which can lead to substantial financial and reputational losses.

  24. 24. An organization experiences a significant data breach due to a zero-day vulnerability. Following the incident, the CISO is tasked with improving the organization's ability to anticipate and defend against future advanced threats. Which of the following would be the MOST effective long-term strategy?

    Information Security Risk Management

    • A. Developing and integrating a proactive threat intelligence program.
    • B. Purchasing next-generation firewalls with advanced intrusion prevention capabilities.
    • C. Implementing a robust patch management program for all systems.
    • D. Investing heavily in security awareness training for all employees.
    Show answer

    A. Developing and integrating a proactive threat intelligence program.

    A zero-day vulnerability implies an unknown threat. While other options address known vulnerabilities or general defenses, a proactive threat intelligence program specifically focuses on gathering, analyzing, and acting upon information about emerging threats, attacker tactics, and vulnerabilities *before* they are exploited. This enables the organization to anticipate and better defend against future advanced and unknown threats in the long term.

  25. 25. A global e-commerce company experiences a data breach involving customer credit card information. The incident response team has contained the breach and is now in the recovery phase. Which of the following is the MOST critical activity during the recovery phase to prevent recurrence and restore normal operations?

    Information Security Risk Management

    • A. Notifying affected customers and regulatory bodies about the breach.
    • B. Conducting a comprehensive post-incident review to identify root causes and lessons learned.
    • C. Restoring affected systems from known good backups and verifying data integrity.
    • D. Implementing enhanced security monitoring and intrusion detection systems.
    Show answer

    B. Conducting a comprehensive post-incident review to identify root causes and lessons learned.

    While restoring systems and implementing new controls are crucial, the 'MOST critical' activity to prevent recurrence and improve future response is the post-incident review. This review identifies the root causes, evaluates the effectiveness of the response, and generates lessons learned, which are essential for long-term improvement and preventing similar incidents.

Certified Information Security Manager (CISM) flashcards

Tap a card to flip it. 180 flashcards in the full deck.

  • Modular Incident Response Playbooks

    Flip card

    Incident response documentation structured into reusable components or modules that can be combined and adapted for various incident types and scenarios.

    • Promotes consistency while allowing flexibility.
    • Easier to update and maintain than monolithic playbooks.
    • Supports automation and orchestration efforts.
    Study this card →
  • Business-Security Alignment

    Flip card

    The process of ensuring that information security strategies, controls, and investments support and enable an organization's overall business objectives.

    • Requires communication between security and business leaders.
    • Involves understanding business risk appetite.
    • Ensures security is a business enabler, not just a cost center.
    Study this card →
  • Risk Treatment Options

    Flip card

    Strategies an organization can employ to address identified risks, including avoidance, mitigation/remediation, transfer, and acceptance.

    • Should align with risk appetite.
    • Involves cost-benefit analysis.
    • Selected based on risk level and business impact.
    Study this card →
  • Information Security Governance

    Flip card

    Information security governance is the system by which an organization directs and controls information security activities, ensuring alignment with business objectives, regulatory requirements, and risk tolerance.

    • Provides strategic direction.
    • Defines roles, responsibilities, and decision-making processes.
    • Ensures compliance and manages risk at an organizational level.
    Study this card →
  • DRP Communication Plan

    Flip card

    A component of the Disaster Recovery Plan that outlines how and when to communicate with internal and external stakeholders during and after a disaster.

    • Addresses legal, regulatory, and ethical obligations.
    • Manages reputation and maintains trust.
    • Specifies communication channels, content, and responsible parties.
    Study this card →
  • Risk-adjusted ROI for Security

    Flip card

    A financial metric that quantifies the return on investment for security initiatives, factoring in the reduction of potential losses (risk mitigation) and the cost of the security controls.

    • Demonstrates financial value of security.
    • Relevant for executive and board-level reporting.
    • Considers both cost of control and averted loss.
    Study this card →
  • Inter-Application Dependency Mapping

    Flip card

    The process of identifying and documenting the relationships and dependencies between different applications, systems, and services within an organization.

    • Crucial for effective disaster recovery planning.
    • Ensures applications are restored in the correct sequence.
    • Helps prevent cascading failures during recovery.
    Study this card →
  • Cross-training

    Flip card

    The process of training employees to perform job functions outside of their primary responsibilities, often related to critical tasks or backup roles.

    • Reduces reliance on single individuals for critical tasks.
    • Improves organizational resilience and flexibility.
    • Enhances employee skill sets and career development.
    Study this card →
  • Mitigating Single Point of Failure (BCP)

    Flip card

    Strategies employed within a Business Continuity Plan to prevent a single component, system, or vendor from causing a complete disruption of critical business operations.

    • Involves redundancy, diversification, and alternative solutions.
    • Critical for high-impact dependencies.
    • Goes beyond contractual assurances to actual operational resilience.
    Study this card →
  • Incident Response Policy

    Flip card

    A formal document that establishes the organization's approach to incident response, outlining objectives, roles, responsibilities, and guiding principles.

    • Provides strategic direction for incident management.
    • Defines authority and scope for incident responders.
    • Ensures consistency and compliance across the organization.
    Study this card →
  • Recovery Point Objective (RPO)

    Flip card

    The maximum amount of data (measured in time) that an organization can afford to lose during a disaster or incident.

    • Determined by business impact analysis.
    • Dictates backup frequency and replication strategies.
    • Expressed as a time interval (e.g., 1 hour, 24 hours).
    Study this card →
  • Mean Time To Detect (MTTD)

    Flip card

    The average time it takes an organization to identify a security incident from the moment it began.

    • Measures the efficiency of monitoring and alerting systems.
    • A lower MTTD indicates better visibility and faster initial response.
    • Crucial for minimizing the impact of incidents by enabling early action.
    Study this card →
  • Business Impact Analysis (BIA)

    Flip card

    A systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.

    • Identifies critical business functions and processes.
    • Determines recovery time objectives (RTO) and recovery point objectives (RPO).
    • Essential for prioritizing security controls and resilience efforts.
    Study this card →
  • Intangible Costs of Incidents

    Flip card

    Non-monetary losses resulting from a security incident that are difficult to quantify but can significantly impact an organization's long-term viability.

    • Includes damage to reputation, customer trust, and brand value.
    • Can lead to loss of market share and future revenue.
    • Often more substantial in the long run than direct costs.
    Study this card →
  • Disaster Recovery Failback

    Flip card

    The process of restoring business operations from the disaster recovery site back to the primary production site after a disaster has been resolved.

    • Often more complex than the initial failover due to data synchronization challenges.
    • Requires careful planning to avoid data loss and minimize business disruption.
    • A critical, often overlooked, phase of the overall disaster recovery lifecycle.
    Study this card →
  • Federated Incident Response Model

    Flip card

    An incident response model that combines elements of centralized and distributed approaches, allowing local teams to handle incidents independently while a central team provides governance, shared services, and manages major incidents.

    • Balances local autonomy with central oversight.
    • Promotes consistency while enabling flexibility.
    • Effective for large, geographically dispersed organizations.
    Study this card →
  • Mean Time To Remediate (MTTR)

    Flip card

    The average time it takes for an organization to resolve a detected security vulnerability or incident from the point of discovery to full resolution.

    • Measures efficiency of remediation processes.
    • High MTTR indicates remediation bottlenecks.
    • Influenced by patch management and incident response effectiveness.
    Study this card →
  • Cold Site

    Flip card

    A disaster recovery site that has basic infrastructure (power, cooling, space) but lacks specific hardware, software, or data. It requires significant time and effort to become operational.

    • Lowest cost DR option.
    • Longest recovery time (RTO).
    • Suitable for non-critical systems or unique hardware requirements with budget constraints.
    Study this card →
  • Scalable Incident Response Structure

    Flip card

    An incident response team organization that can dynamically adjust its size, resources, and command structure based on the severity and complexity of an incident.

    • Allows for efficient resource allocation.
    • Ensures appropriate response for all incident types.
    • Prevents teams from being overwhelmed or underutilized.
    Study this card →
  • Risk Treatment Strategies

    Flip card

    Risk treatment strategies are the approaches an organization takes to manage identified risks, typically categorized as Avoid, Transfer, Mitigate, or Accept.

    • Avoid: Eliminate the activity causing the risk.
    • Transfer: Shift the risk to a third party (e.g., insurance).
    • Mitigate: Reduce the likelihood or impact of the risk.
    Study this card →
  • Incident Commander

    Flip card

    The individual responsible for the overall management of a security incident, including strategic direction, operational planning, and resource allocation.

    • Single point of authority during an incident.
    • Ensures effective communication and coordination.
    • Focuses on achieving incident response objectives.
    Study this card →
  • Forensic Readiness

    Flip card

    The organization's ability to collect, preserve, and analyze digital evidence in a legally sound and forensically sound manner during and after a security incident.

    • Crucial for legal action, regulatory compliance, and post-incident analysis.
    • Requires predefined procedures and trained personnel.
    • Evidence must be collected without alteration to maintain its integrity.
    Study this card →
  • Threat Intelligence

    Flip card

    Threat intelligence is evidence-based knowledge, including context, mechanisms, indicators, implications and actionable advice, about an existing or emerging menace or hazard to assets.

    • Proactive, not reactive.
    • Informs security decisions and defenses.
    • Covers TTPs (Tactics, Techniques, Procedures) of adversaries.
    Study this card →
  • Post-Incident Review (Lessons Learned)

    Flip card

    A formal process conducted after a security incident to analyze what happened, evaluate the effectiveness of the response, identify root causes, and determine improvements.

    • Critical for continuous improvement.
    • Identifies root causes.
    • Informs policy and control updates.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.