Courseiva
mediumMultiple Choice

CISM Practice Question: A company's incident response team is handling a…

A company's incident response team is handling a confirmed ransomware infection that has encrypted files on several servers. The IT director requests that the team immediately restore data from backups to minimize downtime. However, the team suspects that the backup repository may also be compromised because the attacker had administrative credentials. What is the BEST course of action?

⚠ Common exam trap

Watch out — candidates often assume a backup repository can be cleaned or verified as safe, overlooking that an attacker with administrative credentials could have compromised the backup system itself, making offline backups the only reliable recovery source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rebuild the servers from scratch and restore from an offline backup taken before the compromise.

Restoring from an offline backup taken before the compromise ensures that the restored data is free of the ransomware and that the backup itself was not encrypted or tampered with. Since the attacker had administrative credentials, any online backup repository could have been accessed and compromised, making offline backups the only trustworthy source. This approach also eliminates the risk of re-infection by rebuilding the servers from scratch, ensuring no residual malware remains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Proceed with restoration from the most recent backup to restore operations quickly.

    Why it's wrong here

    Restoring immediately risks reinstating attacker-planted malware or re-encrypting data, since the repository may be compromised. It is tempting because rapid recovery minimises downtime, but restoration must await validation that backups are clean and free of the attacker's persistence.

  • ✓

    Rebuild the servers from scratch and restore from an offline backup taken before the compromise.

    Why this is correct

    Rebuilding from scratch eliminates attacker persistence—malware, backdoors, scheduled tasks—that would reinfect restored data. Restoring from an offline backup taken before the compromise satisfies the stem's constraint: the online repository may be tainted by stolen administrative credentials. Offline media is physically isolated, so it cannot have been encrypted or altered by the attacker.

  • ✗

    First, clean the backup repository and verify integrity before restoring to prevent re-infection.

    Why it's wrong here

    Cleaning the repository before verifying integrity risks destroying the only trustworthy recovery point and presumes the compromise is removable. It is tempting because it addresses suspected tampering, but the correct approach isolates and validates backups first, then restores from a confirmed-clean copy.

  • ✗

    Engage law enforcement before any restoration activities.

    Why it's wrong here

    Engaging law enforcement is advisable but does not resolve whether backups are safe to restore, so it cannot precede containment and validation. It is tempting because ransomware is criminal activity, yet the immediate technical priority is preventing re-infection from compromised backups.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.