CISM Incident Management Practice Question
An organization has just experienced a malware outbreak that was contained by isolating affected endpoints. Before restoring the isolated systems to normal operation, the incident response team must decide what activity comes next in the response lifecycle. Which of the following should the team perform NEXT?
⚠ Common exam trap
The trap here is assuming that containment equals resolution, when containment merely stops the spread and eradication must occur before recovery or incident closure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eradicate the malware and remediate the root cause on affected systems before returning them to production.
The incident response lifecycle moves from preparation to detection and analysis, containment, eradication, recovery, and post-incident activity. Once containment has stopped the spread, the team must eradicate the malware and remediate the root cause before systems are returned to production. Recovery without eradication invites reinfection, while review and notification are either parallel obligations or later-phase activities. Eradication is the logical next technical step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a full lessons-learned review and close the incident as resolved.
Why it's wrong here
Lessons-learned review and incident closure occur in the post-incident phase, after eradication and recovery are complete. Performing them now would leave systems still infected or unremediated while the team declares victory. This premature closure can also discard the operational context needed for accurate analysis and improvement.
- ✗
Begin recovery by reconnecting all isolated endpoints to the production network immediately.
Why it's wrong here
Reconnecting isolated endpoints before eradicating the malware would allow the infection to spread again or resume command-and-control communication. Recovery must follow successful eradication and verification. Skipping eradication inverts the response lifecycle and typically results in repeated containment cycles, wasted effort, and extended business disruption.
- ✓
Eradicate the malware and remediate the root cause on affected systems before returning them to production.
Why this is correct
After containment, the next phase is eradication, which removes the malicious code, closes the initial access vector, and remediates the underlying weakness. Returning systems to production before eradication risks immediate reinfection. Eradication may include reimaging, patching, credential resets, and removing persistence mechanisms, and it must be verified before recovery begins so that restored systems are clean and stable.
- ✗
Notify external regulators and law enforcement before any technical remediation is attempted.
Why it's wrong here
Notification obligations depend on legal and regulatory assessment and the nature of the incident; they do not replace the technical eradication step in the response lifecycle. Notifying before remediation does not remove the malware or close the access vector, so systems remain at risk. Notification is typically coordinated in parallel with response activities, not used as a substitute for eradication.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.