Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

During a suspected insider data theft investigation, the incident response team discovers that the suspect's laptop is still powered on and logged in. Legal counsel advises that evidence must be preserved for potential litigation. Which of the following actions should the team take FIRST?

⚠ Common exam trap

The trap here is prioritizing immediate containment over evidence preservation, when volatile data must be captured first to avoid permanently losing critical forensic artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture volatile data such as memory and network connections, then isolate the system from the network.

Forensic best practice is to capture volatile data before isolating or powering down a live system. Memory, active network connections, and encryption keys can vanish on shutdown or network disconnection, and they may be crucial to proving insider theft. After volatile data is secured, isolating the system prevents remote tampering and further exfiltration while preserving the remaining evidence for legal use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Capture volatile data such as memory and network connections, then isolate the system from the network.

    Why this is correct

    Capturing volatile data first preserves memory-resident evidence, active network connections, and encryption keys that would be lost on shutdown. Isolating the system from the network afterward prevents remote tampering or further data exfiltration while maintaining the system state. This sequence aligns with forensic best practices and supports legal preservation requirements, making it the most defensible first action in this scenario.

  • ✗

    Immediately shut down the laptop to prevent the suspect from deleting evidence remotely.

    Why it's wrong here

    Shutting down the laptop can destroy volatile evidence such as running processes, network connections, encryption keys in memory, and unsaved artifacts. While remote deletion is a concern, the immediate loss of volatile data may outweigh that risk. Proper forensic handling prioritizes capturing volatile evidence before any shutdown, making this action premature and potentially damaging to the investigation.

  • ✗

    Disconnect the laptop from the network immediately and begin imaging the hard drive.

    Why it's wrong here

    Disconnecting from the network immediately may prevent remote tampering, but it also cuts off access to live network connections and can trigger encryption or lockout mechanisms. Imaging the hard drive without first capturing volatile data loses memory-resident evidence. This approach skips a critical forensic step and may reduce the completeness and admissibility of the evidence collected.

  • ✗

    Ask the suspect to remain logged in while the team interviews them about the alleged activity.

    Why it's wrong here

    Interviewing the suspect while the system remains active creates opportunities for evidence tampering, remote wiping, or alerting accomplices. It also risks contaminating the investigation and complicating legal proceedings. The priority is to preserve evidence in a forensically sound manner, not to conduct interviews before volatile data is captured and the system is isolated.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.