Courseiva
hardMultiple ChoiceObjective-mapped

Most Effective Eradication Strategy for APTs with Multiple Backdoors

An organization is compromised by an APT that has established multiple backdoors across the network. What is the most effective eradication strategy?

Quick Answer

The answer is to rebuild all affected systems from trusted backups after ensuring the attack vector is closed. This is the most effective eradication strategy for APTs with multiple backdoors because advanced persistent threats often embed deeply nested persistence mechanisms, such as rootkits or scheduled tasks, that can survive individual removal attempts; a full rebuild from a clean, verified backup guarantees that every hidden backdoor is eliminated at the system level. On the Certified Information Security Manager CISM exam, this question tests your understanding of the eradication phase in incident response, where the key principle is that containment and monitoring are not sufficient for removal—only a trusted rebuild ensures complete eradication. A common trap is choosing to isolate or manually remove backdoors, which fails against sophisticated APTs that may have redundant footholds. Memory tip: think “Nuke and Restore”—when an APT has multiple backdoors, you cannot surgically remove them; you must rebuild from a trusted source to achieve true eradication.

⚠ Common exam trap

The CISM exam often tests the distinction between containment (isolating segments) and eradication (removing the threat), and candidates mistakenly choose isolation as the final step instead of recognizing that eradication requires complete system rebuild from trusted media.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rebuild all affected systems from trusted backups after ensuring the attack vector is closed.

Rebuilding all affected systems from trusted backups ensures that any backdoors, rootkits, or persistence mechanisms left by the APT are completely removed. This approach is the most effective because APTs often deploy multiple, redundant backdoors that may not all be discovered through individual removal. Closing the attack vector first prevents re-infection during the rebuild process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Monitor network traffic for anomalies.

    Why it's wrong here

    Incorrect: Monitoring is detection, not eradication.

  • Remove each backdoor individually using forensics.

    Why it's wrong here

    Incorrect: Time-consuming and may miss backdoors; attacker can hide them.

  • Rebuild all affected systems from trusted backups after ensuring the attack vector is closed.

    Why this is correct

    Correct: Ensures complete removal of persistence.

  • Isolate compromised segments from the rest of the network.

    Why it's wrong here

    Incorrect: Isolation is containment, not eradication.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During the eradication phase of an incident response, which action is MOST critical to ensure the threat is fully removed?

medium
  • A.Delete the malware files from the system.
  • B.Reset passwords for all user accounts.
  • C.Update antivirus signatures.
  • D.Reimage all affected systems from known-good backups.

Why D: Reimaging all affected systems from known-good backups is the most critical action during the eradication phase because it ensures complete removal of the threat, including any rootkits, persistence mechanisms, or hidden malware that may survive simple file deletion or signature-based scans. This approach eliminates the risk of residual compromise, as the system is restored to a trusted state from a verified backup, which is essential for environments where the integrity of the operating system and applications cannot be guaranteed after an incident.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.