CISM Incident Management Practice Question
A security operations centre (SOC) analyst receives an alert that a production database server is transmitting large volumes of customer data to an external IP address. The analyst confirms the traffic is malicious. According to CISM best practices, which of the following should the analyst do FIRST?
⚠ Common exam trap
The trap here is assuming that forensic preservation or executive notification must happen before any containment action, when in fact stopping active data loss takes precedence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the database server from the network to contain the data exfiltration.
Once an analyst validates that malicious exfiltration is occurring, the immediate priority is to stop the loss of business data. Containment, such as isolating the affected server, halts the ongoing damage while preserving the environment for investigation. Notification, deep forensic imaging, and broad log review are all necessary activities, but they follow or accompany containment rather than preceding it, because every minute of delay increases data loss and regulatory exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the database server from the network to contain the data exfiltration.
Why this is correct
Containment is the immediate priority once an incident is confirmed, because ongoing exfiltration causes continuous business and regulatory harm. Isolating the server stops the loss of customer data while preserving the system state for later forensic analysis and eradication. This aligns with the incident response lifecycle, where containment follows detection and precedes recovery. Delaying containment to gather more information or notify stakeholders allows the attacker to continue extracting data.
- ✗
Review firewall and proxy logs to determine the full scope of the exfiltration.
Why it's wrong here
Scoping the incident is necessary, but performing extensive log review before containing the threat allows the exfiltration to continue. The analyst already confirmed the traffic is malicious, so further investigation can proceed after the server is isolated. CISM distinguishes between validating an incident and responding to it. Once validation is complete, containment takes priority over expanded analysis.
- ✗
Notify the chief information security officer (CISO) and legal counsel of the suspected breach.
Why it's wrong here
Notification is important but is not the first action when data is actively leaving the environment. Escalation and legal engagement should occur in parallel or immediately after containment begins, not before it. If the analyst stops to notify executives while exfiltration continues, the organisation suffers additional data loss. CISM emphasises protecting business assets first, then communicating according to the escalation plan.
- ✗
Capture a full memory image of the database server before taking any other action.
Why it's wrong here
Forensic preservation is valuable, but volatile evidence collection must not take precedence over stopping active data loss. A full memory capture can take considerable time, during which the attacker continues exfiltrating customer records. The correct sequence is to contain the incident while preserving evidence in a way that does not destroy it, for example by isolating the host rather than powering it off. Preservation supports, but does not replace, containment.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.