Courseiva
mediumMultiple ChoiceObjective-mapped

CISM Practice Question: A company's incident response team is conducting…

A company's incident response team is conducting a tabletop exercise. They are discussing the steps after containment to prevent recurrence. The facilitator asks: 'What is the MOST important next step after containing an incident?' The team considers several options.

⚠ Common exam trap

A common misconception in incident response is that updating the incident response plan or conducting lessons learned is the immediate next step after containment. However, the CISM framework emphasizes that root cause analysis must precede any plan updates to ensure the changes address the actual vulnerability and prevent recurrence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Identify the root cause of the incident

After containment, the most critical step is identifying the root cause to understand how the incident occurred and to implement effective remediation measures. Without root cause analysis, the organization cannot ensure that the same vulnerability or attack vector will not be exploited again, making containment temporary at best. This aligns with the NIST SP 800-61 incident response lifecycle, which places eradication and recovery after containment, driven by root cause identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identify the root cause of the incident

    Why this is correct

    Root cause analysis is essential to prevent recurrence by addressing the underlying vulnerability or process gap.

  • Update the incident response plan with lessons learned

    Why it's wrong here

    Updating the plan is part of post-incident review, which occurs after root cause analysis and remediation.

  • Forensically image all affected systems

    Why it's wrong here

    Forensic imaging is part of containment and evidence preservation, not the immediate next step for prevention.

  • Notify law enforcement about the incident

    Why it's wrong here

    Notification to law enforcement may be required but is not the primary action for prevention; it is typically done during or after containment.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.