hardMultiple SelectObjective-mapped
CISM Practice Question: An incident response team is analyzing a phishing…
An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse post-compromise artifacts (like browser history) with primary IOCs, or think that personal information (phone number) or the company's own website are relevant indicators, when in fact the core IOCs for a phishing email are the sender's IP and the malicious payload identifier.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP address of the sending server.
The correct options are B and C. The IP address of the sending server is a critical IOC because it identifies the source infrastructure used to deliver the phishing email, enabling network-level blocks and threat intelligence correlation. The malicious URL or attachment hash is another key IOC as it represents the payload that compromised the credentials, allowing for signature-based detection and blocking. The other options (browser history, personal phone number, company website) are not primary IOCs from the phishing email itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's browser history.
Why it's wrong here
Browser history is not a primary IOC for the phishing email itself; it is a post-compromise artifact that may show subsequent activities but does not directly identify the phishing source.
- ✓
The IP address of the sending server.
Why this is correct
The IP address of the sending server is a critical IOC as it identifies the source infrastructure, enabling network-level blocking and threat intelligence correlation.
- ✓
The malicious URL or attachment hash.
Why this is correct
The malicious URL or attachment hash is a key IOC that can be used to detect and block the phishing payload across other systems and users.
- ✗
The user's personal phone number.
Why it's wrong here
The user's personal phone number is not relevant to the technical analysis of the phishing email and is not considered an IOC.
- ✗
The company's public website.
Why it's wrong here
The company's public website is unrelated to the phishing attack; it is the target of the attack, not an indicator of compromise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.