CISM Incident Management Practice Question
An organisation is defining the criteria its incident response team will use to determine when an incident has been successfully contained and eradication can begin. Which TWO of the following are the MOST appropriate criteria for that decision? (Choose two.)
⚠ Common exam trap
The trap here is accepting restored business operations or executive assurances as proof of containment, when containment is defined by the elimination of the adversary's access and control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker's command-and-control infrastructure has been sinkholed and no new beaconing is observed from monitored networks
Containment is complete when the adversary can no longer operate: every access path and persistence mechanism has been removed, and command-and-control has been disrupted so no implants can receive instructions. These are verifiable technical conditions. Business resumption, executive assurances, and forensic engagement are useful signals or actions but do not prove the threat has been neutralised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The external forensic firm has been formally engaged and has begun its investigation
Why it's wrong here
Engaging a forensic firm starts the investigative process; it does not demonstrate that the attacker has been stopped. The adversary may still hold access while the investigation is underway. Third-party engagement is a resourcing and assurance step, not a containment criterion, and treating it as one would allow eradication to begin prematurely.
- ✓
The attacker's command-and-control infrastructure has been sinkholed and no new beaconing is observed from monitored networks
Why this is correct
Sinkholing command-and-control and confirming that no hosts continue to beacon provides concrete evidence that the adversary has lost remote control of compromised systems. This is a strong, observable containment indicator because active implants would keep attempting to reach their infrastructure. It directly demonstrates that the attacker's ability to operate within the environment has been disrupted.
- ✓
All attacker-controlled access paths and persistence mechanisms have been identified and removed
Why this is correct
Eradication is only safe once every foothold the attacker established has been found and eliminated. If any backdoor, scheduled task, or compromised credential remains, the attacker can re-enter during recovery and the incident reopens. Confirming the removal of all access paths and persistence is therefore a core containment criterion before moving to the eradication and recovery phases.
- ✗
The chief information security officer has verbally confirmed to the board that the threat has been neutralised
Why it's wrong here
Executive assurance is not technical evidence of containment. A verbal statement, however senior, cannot confirm that persistence mechanisms were removed or that the adversary lost access. Decisions to move from containment to eradication must rest on verified technical findings and defined criteria, with executive communication following rather than substituting for that verification.
- ✗
The affected business unit has confirmed that normal transaction volumes have resumed
Why it's wrong here
Restored transaction volume indicates recovery, not containment. It can even be misleading if operations resume while the attacker still has access, allowing renewed compromise under cover of normal activity. Business resumption is an outcome measured after eradication and recovery, not a criterion for deciding that containment is complete.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.