Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

An organization has just completed containment of a malware outbreak. The incident manager is preparing to transition the incident to the eradication and recovery phase. Which activity should occur FIRST during this transition?

⚠ Common exam trap

Watch out — candidates often confuse recovery with eradication, assuming that restoring from backup resolves the incident before the root cause has been removed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify and remove the root cause and all remnants of the malware from affected systems

The incident response lifecycle moves from preparation to detection and analysis, containment, eradication, recovery, and post-incident activity. Once containment is achieved, the next phase is eradication, which removes the root cause and residual threat. Recovery, regulatory notification, and lessons learned come later. Performing eradication before recovery prevents reinfection and ensures that restored systems are not compromised again by the same vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identify and remove the root cause and all remnants of the malware from affected systems

    Why this is correct

    Eradication focuses on eliminating the root cause and any residual malicious components so the threat cannot recur. Transitioning from containment to eradication means the organization has stabilized the situation and can now remove the threat. Recovery, which follows, restores systems to normal operation. Performing eradication first prevents reinfection during recovery and is the defining activity of this phase.

  • ✗

    Notify external regulators of the incident in accordance with legal requirements

    Why it's wrong here

    Regulatory notification may be required, but it is triggered by legal and compliance criteria and often occurs after the organization understands the scope and impact. It is not the first activity of the eradication and recovery transition. Premature notification without accurate scope information can create compliance problems. The immediate focus should be on removing the threat and restoring systems safely.

  • ✗

    Restore all affected systems from the most recent backups and return them to production

    Why it's wrong here

    Restoration is part of the recovery phase, which follows eradication. Restoring systems before the root cause is removed risks immediate reinfection and wasted effort. Backups may also contain the malware if the compromise predates the backup. CISM sequencing requires eradication before recovery to ensure that restored systems remain clean and that the vulnerability or vector is closed.

  • ✗

    Conduct a lessons-learned meeting with all incident responders

    Why it's wrong here

    Lessons learned is a post-incident activity performed after recovery is complete and the incident is closed. Conducting it during the transition to eradication would be premature because the full timeline and root cause are not yet established. CISM places lessons learned at the end of the incident lifecycle to capture accurate findings and improve future response.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.