Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

An organization's incident response team has contained a malware outbreak, but the attacker's initial access vector remains unknown. Which activity should be performed to reduce the likelihood of recurrence?

⚠ Common exam trap

The trap here is treating recovery and closure as the end of the incident, when an unknown access vector means the root cause has not been addressed and the environment remains exposed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a root cause analysis to identify and remediate the initial access vector.

When the initial access vector is unknown, the highest priority is a structured root cause analysis to determine how the attacker entered and to eliminate that pathway. This prevents recurrence and feeds lessons learned into control improvements, monitoring enhancements, and plan updates. Recovery, signature updates, and awareness communications are useful supporting activities, but none of them replaces identifying and closing the actual entry point.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify all employees about the incident and remind them of security policies.

    Why it's wrong here

    Employee awareness is valuable, but a general reminder does not identify or fix the specific weakness that allowed access. If the vector was a technical misconfiguration or unpatched service rather than user behavior, awareness messaging misses the point. Communication should follow, not substitute for, a structured investigation that determines the actual cause and the corrective actions required.

  • ✗

    Increase the frequency of antivirus signature updates on all endpoints.

    Why it's wrong here

    Updating antivirus signatures improves detection of known malware but does not address the unknown entry path. If the attacker exploited a vulnerable public-facing service or valid credentials, signature updates provide little protection. Without root cause analysis, the organization cannot confirm whether the entry point has been closed, so signature updates alone are an incomplete and potentially misleading response.

  • ✓

    Perform a root cause analysis to identify and remediate the initial access vector.

    Why this is correct

    Root cause analysis examines logs, forensic artifacts, and timeline data to determine how the attacker gained entry, such as a phishing email, exposed service, or stolen credential. Identifying and remediating that vector prevents recurrence and informs improvements to controls, monitoring, and the incident response plan. It also supports lessons learned and any regulatory or insurance reporting requirements.

  • ✗

    Close the incident and restore affected systems from backups.

    Why it's wrong here

    Restoring systems and closing the incident without identifying the initial access vector leaves the underlying vulnerability in place. The attacker, or another actor using the same technique, can re-compromise the environment. Recovery actions should follow eradication of the root cause, not replace it, otherwise the organization risks repeated incidents and eroded stakeholder confidence in the response process.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.