Courseiva
Incident Management →hardMultiple Choice

CISM Incident Management Practice Question

During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?

⚠ Common exam trap

The trap here is equating containment with shutting the system down, when isolation actually contains the threat while preserving the volatile evidence needed for investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the server from the network at the switch or host firewall level while keeping it powered on for volatile data collection

The best balance is to contain the system without destroying volatile evidence. Network isolation stops malicious communication and lateral movement while leaving memory, running processes, and active connections intact for collection. Powering off, prolonged passive monitoring, or immediate rebuild each sacrifice either containment or investigative capability, so they fail to meet both requirements simultaneously.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately power off the server to stop all malicious activity and prevent further data loss

    Why it's wrong here

    Powering off a server destroys volatile evidence such as running processes, network connections, and memory-resident malware, and it can also corrupt encrypted volumes. It stops activity but severely degrades investigative capability and may prevent determining the full scope of compromise. This approach sacrifices evidence preservation, which the scenario explicitly requires, so it is not the best balance.

  • ✗

    Rebuild the server from a known-good image immediately to restore service and remove any attacker foothold

    Why it's wrong here

    Rebuilding removes the attacker but also destroys the evidence needed to determine initial access, scope, and persistence mechanisms. Without that understanding, the organization cannot confirm whether other systems are compromised or whether the root cause has been addressed, risking reinfection. Immediate rebuild prioritizes recovery over investigation and does not balance the two objectives stated in the scenario.

  • ✓

    Isolate the server from the network at the switch or host firewall level while keeping it powered on for volatile data collection

    Why this is correct

    Network isolation stops command-and-control communication and lateral movement while keeping the system running so memory, active connections, and process state can be captured. This preserves volatile evidence and supports scoping the intrusion, satisfying both containment and investigation needs. It is the standard balanced approach when a system must be contained without destroying forensic value.

  • ✗

    Leave the server online and continue monitoring the command-and-control traffic to gather more intelligence on the attacker

    Why it's wrong here

    Continued monitoring can yield threat intelligence, but it allows the attacker to maintain persistence, exfiltrate data, and pivot to other systems. The scenario requires both containment and investigation, and unrestricted monitoring provides no containment. Unless a deliberate, well-resourced deception operation is authorized, this exposure is unacceptable and fails the containment requirement.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.