Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

A security analyst receives an alert indicating that a workstation is communicating with a known malicious command-and-control server. The analyst confirms the alert is a true positive. According to CISM best practices, which of the following should the analyst do FIRST?

⚠ Common exam trap

The trap here is choosing to shut down or scan the workstation first, which can either destroy evidence or leave the attacker connected, instead of isolating it to contain the threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the workstation from the network to prevent further communication.

When a true positive is confirmed, the immediate priority is containment to stop the threat from spreading or causing further harm. Isolating the workstation cuts off command-and-control communication while preserving the system for investigation. This follows the standard incident response sequence of identification, containment, eradication, and recovery, and supports both security and forensic objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shut down the workstation to stop the malware.

    Why it's wrong here

    Shutting down the workstation may destroy volatile evidence in memory, such as running processes, network connections, and encryption keys, which are valuable for forensic analysis. Isolation is preferred because it preserves the system state while cutting off network communication. Powering off can also trigger anti-forensic mechanisms in some malware. Containment should be done without destroying evidence.

  • ✗

    Notify the CEO and board of directors about the incident.

    Why it's wrong here

    Notifying executive leadership is premature at this early stage of a single-workstation incident. Escalation should follow the incident response plan's severity criteria. Involving the CEO and board immediately could cause unnecessary alarm and divert attention from containment. The analyst should first contain the threat and then follow escalation procedures based on severity.

  • ✗

    Run a full antivirus scan on the workstation.

    Why it's wrong here

    Running a scan is a remediation step, but it does not immediately stop the active communication with the command-and-control server. The workstation remains connected and the attacker could continue to operate. Containment must come first to prevent further damage or data loss. Scanning can be performed after isolation as part of the investigation and cleanup.

  • ✓

    Isolate the workstation from the network to prevent further communication.

    Why this is correct

    Isolating the workstation is the immediate containment step that stops the malware from communicating with the command-and-control server and prevents potential lateral movement or data exfiltration. This aligns with the containment phase of incident response. Once isolated, the team can conduct a thorough investigation and remediation without the risk of the attacker continuing to operate.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.