Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

During a major incident, the incident response team determines that a compromised server must be rebuilt immediately to restore a critical service. A forensic analyst objects, noting that the server contains evidence relevant to a pending regulatory investigation. How should the incident manager resolve this conflict?

⚠ Common exam trap

The trap here is treating recovery and evidence preservation as mutually exclusive, when capturing a forensic image allows both objectives to be met.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture a forensic image of the server's storage and volatile memory before rebuilding, then document the evidence handling.

When operational recovery and evidence preservation collide, the incident manager should pursue both by imaging the system before it is rebuilt. A forensic image of storage and memory preserves the artifacts regulators and investigators require while allowing the critical service to be restored. This balanced action aligns with CISM guidance to integrate incident response with legal and regulatory obligations rather than sacrificing one for the other.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Proceed with the rebuild because restoring the critical service takes priority over any investigative activity.

    Why it's wrong here

    Service restoration is important, but unilaterally destroying evidence during a pending regulatory investigation can expose the organization to legal sanctions, spoliation claims, and loss of the ability to determine root cause. CISM expects the incident manager to seek a balanced resolution, not to default to rebuild. Treating restoration as an absolute priority ignores the organization's legal and regulatory obligations.

  • ✗

    Rebuild the server and rely on the SIEM logs to reconstruct the evidence needed for the investigation.

    Why it's wrong here

    SIEM logs capture network and event telemetry but not disk artifacts, memory-resident malware, deleted files, or file system metadata that investigators need. Assuming logs are sufficient risks incomplete evidence and undermines the regulatory investigation. CISM distinguishes between log data and forensic evidence, and rebuilding without imaging the host would permanently lose artifacts the logs cannot reproduce.

  • ✗

    Delay the rebuild until the regulatory investigation concludes so that the server remains untouched.

    Why it's wrong here

    Keeping a compromised server online indefinitely to preserve evidence would prolong service outage and may allow the attacker to maintain persistence or cause further damage. The investigation could take months, making this impractical and harmful to the business. Preservation does not require leaving the system in an insecure state; a forensic image achieves the same evidentiary goal without sacrificing availability.

  • ✓

    Capture a forensic image of the server's storage and volatile memory before rebuilding, then document the evidence handling.

    Why this is correct

    Preserving a forensic image of both persistent storage and volatile memory satisfies the investigator's need for evidence while allowing the rebuild to proceed. This approach respects the pending regulatory investigation and maintains chain of custody, which is essential if the evidence is later challenged. CISM supports continuity of operations balanced with legal preservation, making this the appropriate resolution of the conflict.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.