Greatest Risk of a Poorly Trained Incident Response Team?
Which of the following is the GREATEST risk associated with a poorly trained incident response team responding to a major incident?
Community Votes
83% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests prioritization of forensic preservation over general security controls, with the common trap being confusion between data loss and evidence tampering.
A poorly trained incident response team poses the greatest risk of evidence contamination, which compromises forensic integrity and legal proceedings. Community consensus confirms that preserving chain-of-custody outweighs other operational concerns.
Option A is frequently chosen by candidates who confuse general IT governance principles with incident-specific procedural risks, overlooking how untrained responders directly compromise digital forensics.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Incident response procedures mandate strict forensic protocols to maintain the chain of custody. When a team lacks proper training, they often use non-forensic tools, alter system states, or mishandle storage media, directly contaminating evidence. This destruction invalidates root cause analysis and eliminates legal admissibility, making it the single greatest operational risk.Why the Other Options Are Wrong
Loss of confidential information (B) is a business impact concern, but IR focuses first on containment and investigation rather than absolute data retention. Separation of duty violations (A) relate to administrative access controls and fraud prevention, not immediate tactical response failures. Failure to escalate (D) delays decision-making but does not irreversibly destroy the technical investigation like evidence contamination does.Community Comment Notes
Candidates consistently vote for C, recognizing it as the foundational IR failure. One helpful comment notes that evidence contamination encompasses broader procedural breakdowns, effectively neutralizing all subsequent recovery efforts. Another user clarifies that while data loss and escalation issues occur, they are secondary to the irreversible damage caused by tainted digital artifacts.Exam Strategy
Always prioritize forensic integrity when analyzing incident response scenarios; ask yourself whether the action preserves or destroys the ability to investigate legally. If an option compromises chain-of-custody, it typically represents the highest risk regardless of immediate business impact.
Frequently Asked Questions
Why isn't loss of confidential information the top risk?
While data exposure is critical, incident response prioritizes preserving actionable intelligence. Contaminated evidence makes containment and prevention impossible, causing greater long-term damage.
How does separation of duty relate to incident response?
SoD prevents fraud in daily operations but is not the primary IR failure mode. Untrained responders bypass SoD unintentionally, but evidence destruction remains the direct investigative killer.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →