CISM Incident Management Practice Question
During a major incident, the incident response team determines that the attacker used compromised credentials of a privileged administrator. The team wants to prevent the attacker from re-entering while keeping the business running. Which of the following is the MOST appropriate containment action?
⚠ Common exam trap
The trap here is treating broad system shutdown as the safest containment, when a proportionate credential-focused action contains the threat with far less business disruption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the compromised administrator account and rotate all credentials for privileged accounts.
The most effective containment against credential-based intrusion is to remove the compromised access and invalidate related secrets. Disabling the known compromised administrator account stops the confirmed entry path, while rotating all privileged credentials closes the likely other paths the attacker obtained. This approach contains the threat without unnecessarily halting business operations, which reflects CISM's balance between security response and business continuity. Blanket shutdowns and passive monitoring fail to remove the adversary's access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable full packet capture on the network and continue monitoring for attacker activity.
Why it's wrong here
Monitoring is useful for detection and scoping but does not contain an attacker who already holds valid privileged credentials. Continuing to observe while the attacker retains access allows further compromise and data theft. CISM distinguishes monitoring from containment; once an active intrusion is confirmed, the organisation must act to remove access rather than passively watch. Packet capture can support the investigation but should not replace disabling the compromised account.
- ✗
Reset the password on the compromised administrator account only and force a change at next logon.
Why it's wrong here
Resetting a single password leaves the account enabled and ignores other credentials the attacker may have collected, such as service accounts, API keys, or additional privileged logons. A forced change at next logon does not stop an attacker who already has an active session. CISM containment should eliminate the adversary's access comprehensively. Disabling the account and rotating all privileged credentials is the more complete and reliable action.
- ✓
Disable the compromised administrator account and rotate all credentials for privileged accounts.
Why this is correct
Disabling the compromised account removes the attacker's known access path, and rotating privileged credentials invalidates any other stolen secrets the attacker may hold. This contains the incident without shutting down business operations, which supports the CISM principle of balancing security with business continuity. It also addresses the likelihood that the attacker harvested additional credentials from the compromised administrator's session or memory, closing related entry points.
- ✗
Shut down all servers that the administrator account could access until the investigation is complete.
Why it's wrong here
Shutting down every accessible server is a disproportionate response that causes major business disruption and may destroy volatile evidence. CISM expects containment to be scoped and proportionate, preserving business processes where possible. Disabling the account and rotating credentials achieves containment with far less operational impact. A blanket shutdown also makes it harder to determine which systems were actually compromised, complicating eradication and recovery.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.