Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

During a suspected insider data theft, a security manager discovers that an employee copied sensitive pricing files to a personal cloud drive two weeks ago. Legal counsel has not yet decided whether to pursue legal action. The security manager must decide how to treat the forensic copies of the employee's laptop image and cloud access logs. Which action BEST aligns with evidence handling requirements?

⚠ Common exam trap

The trap here is treating the investigation as purely internal and skipping formal evidence controls, when undecided litigation makes chain of custody and hashing essential from the first acquisition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maintain a documented chain of custody, hash the images, and store them in a restricted evidence repository

When litigation is undecided, the safest course is to preserve evidence so it remains usable in any proceeding. Hashing the forensic images at acquisition, documenting every transfer in a chain of custody, and storing copies in a restricted repository together establish integrity and control. These steps prevent alteration, support authentication, and keep access limited. Continued monitoring without preservation, selective deletion, or broad sharing all risk destroying or contaminating evidence before legal counsel determines the organization's position.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Copy the evidence to a shared network folder so legal, HR, and IT can all review it as needed

    Why it's wrong here

    Broad sharing undermines both evidentiary integrity and confidentiality. Each copy creates an uncontrolled duplicate with no custody record, and shared folders rarely log who accessed or modified files, weakening any future authentication of the evidence. It also spreads sensitive pricing data and personal information to parties with no need to know, increasing privacy and insider-risk exposure. Evidence access must be restricted and logged, not opened to multiple departments through a common share.

  • ✓

    Maintain a documented chain of custody, hash the images, and store them in a restricted evidence repository

    Why this is correct

    Forensic evidence must remain admissible and defensible, which requires verifiable integrity and unbroken custody. Hashing the images at acquisition proves they were not altered, while a documented chain of custody records every transfer, and a restricted repository prevents tampering. Because litigation is still undecided, preserving evidence in this rigorous manner keeps all options open. This approach satisfies both internal investigation needs and potential legal proceedings without prejudging the outcome.

  • ✗

    Allow the employee to continue working normally while quietly monitoring activity to gather more evidence

    Why it's wrong here

    Continued monitoring may yield more intelligence, but it also risks the employee destroying or altering evidence, exfiltrating additional data, and creating further legal exposure. Without preserving the existing laptop image and logs immediately, the organization may lose the very artifacts that establish what happened. Allowing normal access also confuses the investigation's scope and can compromise the integrity of the device before forensic acquisition occurs. Preservation must precede further monitoring decisions.

  • ✗

    Delete the laptop image after extracting only the relevant pricing files to reduce storage and privacy risk

    Why it's wrong here

    Extracting only selected files and discarding the full image destroys context such as deleted artifacts, timestamps, and user activity that may prove intent or reveal additional theft. It also breaks forensic completeness, making the evidence vulnerable to challenge. Privacy concerns are addressed through controlled access and retention policies, not by destroying evidence. Until legal counsel decides on action, the organization must retain the complete, verified image.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.