easyMultiple Choice
CISM Practice Question: That their computer is behaving oddly, and an IT…
A user reports that their computer is behaving oddly, and an IT technician finds a suspicious file in the startup folder. The technician is not sure if this is an incident. What should the technician do FIRST?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate to the security team
When unsure, the best practice is to escalate to the security team to investigate further. Deleting the file could destroy evidence, and scanning may not be sufficient. Option B is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Document the findings and continue monitoring
Why it's wrong here
Documenting and merely monitoring delays escalation; the technician must first report the suspicious startup file through the incident response process so it can be triaged. It is tempting because documentation is part of response, but it is the correct action after triage, not before determining whether an incident exists.
- ✓
Escalate to the security team
Why this is correct
A suspicious file in the startup folder is a potential indicator of compromise requiring specialist triage, so the technician should escalate to the security team immediately. Preserving evidence and avoiding independent containment actions supports the incident response process.
- ✗
Run an antivirus scan
Why it's wrong here
Running an antivirus scan assumes the file is already identified as malware, but the technician is uncertain whether the file constitutes an incident at all. The correct first step is to preserve the file for forensic analysis and check its digital signature, hash, or behaviour in a sandbox to determine if it is malicious. This option is tempting because antivirus software is the standard tool for removing known threats, and it would be correct if the technician had already confirmed the file was malware and needed to remediate.
- ✗
Delete the suspicious file
Why it's wrong here
Deleting the file destroys volatile evidence before the incident response process determines whether it is malicious, hindering investigation and containment. It is tempting as quick remediation, and deletion would be right after an incident is confirmed and evidence preserved, not as the first uncertain step.
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.