CISM Incident Management Practice Question
An organization has just completed containment of a malware outbreak. The incident manager is preparing to transition the incident to the eradication and recovery phase. Which activity should occur FIRST during this transition?
⚠ Common exam trap
Watch out — candidates often confuse recovery with eradication, assuming that restoring from backup resolves the incident before the root cause has been removed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify and remove the root cause and all remnants of the malware from affected systems
The incident response lifecycle moves from preparation to detection and analysis, containment, eradication, recovery, and post-incident activity. Once containment is achieved, the next phase is eradication, which removes the root cause and residual threat. Recovery, regulatory notification, and lessons learned come later. Performing eradication before recovery prevents reinfection and ensures that restored systems are not compromised again by the same vector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify and remove the root cause and all remnants of the malware from affected systems
Why this is correct
Eradication focuses on eliminating the root cause and any residual malicious components so the threat cannot recur. Transitioning from containment to eradication means the organization has stabilized the situation and can now remove the threat. Recovery, which follows, restores systems to normal operation. Performing eradication first prevents reinfection during recovery and is the defining activity of this phase.
- ✗
Notify external regulators of the incident in accordance with legal requirements
Why it's wrong here
Regulatory notification may be required, but it is triggered by legal and compliance criteria and often occurs after the organization understands the scope and impact. It is not the first activity of the eradication and recovery transition. Premature notification without accurate scope information can create compliance problems. The immediate focus should be on removing the threat and restoring systems safely.
- ✗
Restore all affected systems from the most recent backups and return them to production
Why it's wrong here
Restoration is part of the recovery phase, which follows eradication. Restoring systems before the root cause is removed risks immediate reinfection and wasted effort. Backups may also contain the malware if the compromise predates the backup. CISM sequencing requires eradication before recovery to ensure that restored systems remain clean and that the vulnerability or vector is closed.
- ✗
Conduct a lessons-learned meeting with all incident responders
Why it's wrong here
Lessons learned is a post-incident activity performed after recovery is complete and the incident is closed. Conducting it during the transition to eradication would be premature because the full timeline and root cause are not yet established. CISM places lessons learned at the end of the incident lifecycle to capture accurate findings and improve future response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.