CISM Incident Management Practice Question
An organization has experienced a security incident involving unauthorized access to a system containing customer data. The incident response team has contained the incident. According to CISM best practices, which of the following should be performed NEXT?
⚠ Common exam trap
The trap here is thinking that recovery or notification comes immediately after containment, when actually eradication must occur first to prevent recurrence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eradicate the root cause of the incident.
After containment, the incident response team should proceed to eradication to remove the root cause of the incident. This ensures that the threat is eliminated before recovery. Recovery, lessons learned, and customer notification are subsequent steps. CISM emphasizes a structured incident response process, and eradication is the logical next phase after containment to prevent the incident from recurring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify affected customers about the data breach.
Why it's wrong here
Notification may be required, but it is not the immediate next step. The organization must first eradicate the threat and recover systems, while also coordinating with legal counsel to determine notification requirements. Notification timelines are often dictated by law, but the technical response should proceed. This option is a distractor because it focuses on external communication before the incident is fully resolved.
- ✓
Eradicate the root cause of the incident.
Why this is correct
This is correct because after containment, the next phase in the incident response lifecycle is eradication. Eradication involves removing the cause of the incident, such as malware, backdoors, or vulnerabilities, to prevent recurrence. CISM follows the standard incident response phases: preparation, identification, containment, eradication, recovery, and lessons learned. Eradication must be completed before recovery to ensure the environment is clean.
- ✗
Recover the affected systems to normal operations.
Why it's wrong here
Recovery comes after eradication. If systems are recovered before the root cause is eradicated, the incident may recur. This option is a distractor because it skips a critical step. The incident response team must first ensure that the threat is eliminated before restoring operations. CISM emphasizes a methodical approach to incident handling.
- ✗
Conduct a lessons learned session.
Why it's wrong here
Lessons learned is typically conducted after recovery, as part of post-incident activities. It is important but not the immediate next step. The team should first eradicate the threat and recover systems. This option is a distractor because it jumps ahead to a later phase. CISM stresses the importance of following the incident response lifecycle in order.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.