mediumMultiple Choice
CISM Practice Question: After containing an incident, the incident…
After containing an incident, the incident response team is ready to proceed. According to NIST SP 800-61, what is the next phase?
⚠ Common exam trap
Test-takers frequently confuse the order of phases, mistakenly placing recovery before eradication, or thinking communication is a distinct phase rather than a continuous activity throughout the process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eradication
According to NIST SP 800-61 (Computer Security Incident Handling Guide), after containment, the next phase is eradication. Eradication involves removing the root cause of the incident, such as deleting malware, disabling compromised accounts, or patching vulnerabilities, to ensure the threat is fully eliminated before recovery begins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Communication
Why it's wrong here
Communication is not a discrete NIST SP 800-61 lifecycle phase; it is a concurrent activity spanning preparation through post-incident activity. It is tempting because notification and information sharing are mandated throughout handling, but the sequential phase after containment is eradication, then recovery.
- ✗
Recovery
Why it's wrong here
Recovery restores systems only after eradication has removed the root cause and artefacts; jumping straight there leaves the threat able to reinfect. It is tempting because recovery is a real NIST phase and follows eradication, so it would be correct once the malware or vulnerability has been eliminated.
- ✓
Eradication
Why this is correct
NIST SP 800-61 orders the incident response lifecycle as preparation, detection and analysis, containment, eradication, recovery, then post-incident activity. Once containment is complete, eradication follows, removing the root cause, malware or compromised accounts before systems are restored to normal operation.
- ✗
Lessons Learned
Why it's wrong here
Lessons Learned follows eradication and recovery, not containment; NIST SP 800-61 orders containment, eradication, recovery, then post-incident activity. It is tempting because it is a genuine final phase, and would be correct once systems are restored and the incident formally closed.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.