Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

An organization's incident response plan requires that evidence be collected in a forensically sound manner. A responder is about to capture volatile data from a compromised server. Which action BEST preserves the integrity of the evidence?

⚠ Common exam trap

The trap here is treating remediation steps such as rebooting or antivirus scanning as compatible with evidence preservation, when they actually destroy or alter it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the system state, capture volatile data in order of volatility, and maintain a chain of custody.

Sound forensic collection follows the order of volatility, capturing memory and network state before disk, while documenting actions and maintaining chain of custody. Rebooting, powering off, or running antivirus modifies or destroys evidence. CISM stresses that evidence must be preserved in a manner that supports both incident analysis and potential legal or regulatory proceedings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan and allow it to quarantine any detected threats before collecting data.

    Why it's wrong here

    Running antivirus can alter or delete malicious files and modify system state, which contaminates evidence and may destroy indicators of compromise. CISM requires that evidence be preserved without alteration. Remediation activities should follow evidence collection, not precede it, so this action would undermine the forensic integrity of the investigation.

  • ✗

    Reboot the server first to clear any malicious processes before collecting data.

    Why it's wrong here

    Rebooting destroys volatile data such as memory contents, running processes, network connections, and temporary files that are critical for forensic analysis. CISM emphasizes preserving evidence in its original state. Rebooting before collection would irreversibly lose valuable artifacts and potentially tip off attackers, so it is the opposite of a sound forensic approach.

  • ✗

    Immediately power off the server and store the hard drive in a secure location.

    Why it's wrong here

    Powering off the server destroys volatile evidence in memory and may also trigger encryption or anti-forensic mechanisms. While securing the hard drive is important, doing so without first capturing volatile data loses critical artifacts. CISM expects responders to follow the order of volatility, so this action is premature and would compromise the investigation.

  • ✓

    Document the system state, capture volatile data in order of volatility, and maintain a chain of custody.

    Why this is correct

    Forensically sound collection follows the order of volatility, starting with the most perishable data such as memory and network connections, then moving to disk. Documenting the state and maintaining a chain of custody ensures evidence integrity and admissibility. This approach aligns with CISM guidance to preserve evidence properly while supporting incident analysis and any subsequent legal or regulatory actions.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.