Courseiva
mediumMultiple Choice

CISM Practice Question: After containing an incident, the incident…

After containing an incident, the incident response team is ready to proceed. According to NIST SP 800-61, what is the next phase?

⚠ Common exam trap

Test-takers frequently confuse the order of phases, mistakenly placing recovery before eradication, or thinking communication is a distinct phase rather than a continuous activity throughout the process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Eradication

According to NIST SP 800-61 (Computer Security Incident Handling Guide), after containment, the next phase is eradication. Eradication involves removing the root cause of the incident, such as deleting malware, disabling compromised accounts, or patching vulnerabilities, to ensure the threat is fully eliminated before recovery begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Communication

    Why it's wrong here

    Communication is not a discrete NIST SP 800-61 lifecycle phase; it is a concurrent activity spanning preparation through post-incident activity. It is tempting because notification and information sharing are mandated throughout handling, but the sequential phase after containment is eradication, then recovery.

  • ✗

    Recovery

    Why it's wrong here

    Recovery restores systems only after eradication has removed the root cause and artefacts; jumping straight there leaves the threat able to reinfect. It is tempting because recovery is a real NIST phase and follows eradication, so it would be correct once the malware or vulnerability has been eliminated.

  • ✓

    Eradication

    Why this is correct

    NIST SP 800-61 orders the incident response lifecycle as preparation, detection and analysis, containment, eradication, recovery, then post-incident activity. Once containment is complete, eradication follows, removing the root cause, malware or compromised accounts before systems are restored to normal operation.

  • ✗

    Lessons Learned

    Why it's wrong here

    Lessons Learned follows eradication and recovery, not containment; NIST SP 800-61 orders containment, eradication, recovery, then post-incident activity. It is tempting because it is a genuine final phase, and would be correct once systems are restored and the incident formally closed.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.