PE PowerExams Prepare. Practice. Pass.
CIS-SIR · Domain 5 of 7

Risk Calculations and Post Incident Response

About 13% of the CIS-SIR exam — see all 7 domains.

13%
of the exam
39
practice questions
7
domains total

Severity and risk calculation

A security incident's severity can be calculated automatically by a severity calculator that evaluates business-impact factors — the criticality of affected CIs/services, the number of affected users, and other weighted inputs — to produce a severity/priority value. The calculator is rule-driven and configurable: you can define the fields and weights that contribute to the score. The goal is consistent, defensible prioritization rather than analyst guesswork.

  • Risk score / severity is derived from business impact (affected service criticality, asset value) and incident attributes.
  • Calculators are configurable — implementers tune the inputs and weights to match the organization's risk model.
  • (VERIFY) the exact calculator names, default fields, and weight tables for your release, as these have evolved.

Business criticality and the CMDB

Because security incidents reference CMDB CIs, the business criticality of the affected CI/service feeds severity. A compromised business-critical server produces a higher severity than the same compromise on a low-value asset. This CMDB linkage is the bridge that makes risk-based prioritization possible.

Post Incident Review (PIR)

After an incident closes, Post Incident Review captures lessons learned: what happened, how it was handled, what worked, and what should change. PIR is structured (often a questionnaire/assessment) so that findings are consistent and actionable. The output drives continuous improvement — updated runbooks, new playbook steps, tuned calculators, closed gaps. Know that PIR is a defined, post-closure phase (it maps to the Review state) and is part of standardized incident handling, not an ad-hoc afterthought.

Closure and resolution

Closing a security incident requires recording closure information (resolution, close code/notes) and, depending on configuration, completing the review. SLAs stop on closure. Proper closure data is what feeds dashboards, PA, and PIR metrics.


Sample questions from this domain

Three of the 39 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

What is the purpose of the security incident risk calculator?

  • A. To compute a risk score for a security incident based on configured factors and weights
  • B. To assign roles to users
  • C. To rebuild the CMDB
  • D. To parse inbound emails

Why: The risk calculator computes a risk score for security incidents based on configured factors and weights. It does not parse emails, rebuild the CMDB, or assign roles.

Question 2 · medium

What is the primary purpose of a Post Incident Review (PIR) in SIR?

  • A. To rebuild the threat feed
  • B. To create the initial incident record
  • C. To capture lessons learned, evaluate response effectiveness, and identify improvements after an incident is resolved
  • D. To enrich observables in real time

Why: A Post Incident Review captures lessons learned, evaluates response effectiveness, and identifies improvements after resolution. It is not for initial record creation, real-time enrichment, or feed rebuilding.

Question 3 · medium

Which two factors might a security incident risk calculator consider when scoring an incident? (Choose two)

  • A. The instance time zone
  • B. The portal theme color
  • C. The number of knowledge articles
  • D. The severity or category of the incident
  • E. The criticality or business impact of affected configuration items

Why: Risk calculations can weigh affected CI criticality/business impact and incident severity/category. Time zones, knowledge counts, and portal colors are not risk factors.