CISM Incident Management Practice Question
A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?
⚠ Common exam trap
The trap here is choosing to shut down or scan the workstation first, which can either destroy evidence or leave the attacker connected, instead of isolating it to contain the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network to prevent further communication.
When a true positive is confirmed, the immediate priority is containment to stop the threat from spreading or causing further harm. Isolating the workstation cuts off command-and-control communication while preserving the system for investigation. This follows the standard incident response sequence of identification, containment, eradication, and recovery, and supports both security and forensic objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shut down the workstation to stop the malware.
Why it's wrong here
Shutting down the workstation may destroy volatile evidence in memory, such as running processes, network connections, and encryption keys, which are valuable for forensic analysis. Isolation is preferred because it preserves the system state while cutting off network communication. Powering off can also trigger anti-forensic mechanisms in some malware. Containment should be done without destroying evidence.
- ✗
Notify the CEO and board of directors about the incident.
Why it's wrong here
Notifying executive leadership is premature at this early stage of a single-workstation incident. Escalation should follow the incident response plan's severity criteria. Involving the CEO and board immediately could cause unnecessary alarm and divert attention from containment. The analyst should first contain the threat and then follow escalation procedures based on severity.
- ✗
Run a full antivirus scan on the workstation.
Why it's wrong here
Running a scan is a remediation step, but it does not immediately stop the active communication with the command-and-control server. The workstation remains connected and the attacker could continue to operate. Containment must come first to prevent further damage or data loss. Scanning can be performed after isolation as part of the investigation and cleanup.
- ✓
Isolate the workstation from the network to prevent further communication.
Why this is correct
Isolating the workstation is the immediate containment step that stops the malware from communicating with the command-and-control server and prevents potential lateral movement or data exfiltration. This aligns with the containment phase of incident response. Once isolated, the team can conduct a thorough investigation and remediation without the risk of the attacker continuing to operate.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.