CISM Incident Management Practice Question
During a suspected intrusion, the incident response team identifies a compromised server that is actively communicating with an external command-and-control address. The security manager must decide the immediate next action while preserving the ability to perform a thorough investigation. Which of the following actions BEST balances containment with evidence preservation?
⚠ Common exam trap
The trap here is equating containment with shutting the system down, when isolation actually contains the threat while preserving the volatile evidence needed for investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the server from the network at the switch or host firewall level while keeping it powered on for volatile data collection
The best balance is to contain the system without destroying volatile evidence. Network isolation stops malicious communication and lateral movement while leaving memory, running processes, and active connections intact for collection. Powering off, prolonged passive monitoring, or immediate rebuild each sacrifice either containment or investigative capability, so they fail to meet both requirements simultaneously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately power off the server to stop all malicious activity and prevent further data loss
Why it's wrong here
Powering off a server destroys volatile evidence such as running processes, network connections, and memory-resident malware, and it can also corrupt encrypted volumes. It stops activity but severely degrades investigative capability and may prevent determining the full scope of compromise. This approach sacrifices evidence preservation, which the scenario explicitly requires, so it is not the best balance.
- ✗
Rebuild the server from a known-good image immediately to restore service and remove any attacker foothold
Why it's wrong here
Rebuilding removes the attacker but also destroys the evidence needed to determine initial access, scope, and persistence mechanisms. Without that understanding, the organization cannot confirm whether other systems are compromised or whether the root cause has been addressed, risking reinfection. Immediate rebuild prioritizes recovery over investigation and does not balance the two objectives stated in the scenario.
- ✓
Isolate the server from the network at the switch or host firewall level while keeping it powered on for volatile data collection
Why this is correct
Network isolation stops command-and-control communication and lateral movement while keeping the system running so memory, active connections, and process state can be captured. This preserves volatile evidence and supports scoping the intrusion, satisfying both containment and investigation needs. It is the standard balanced approach when a system must be contained without destroying forensic value.
- ✗
Leave the server online and continue monitoring the command-and-control traffic to gather more intelligence on the attacker
Why it's wrong here
Continued monitoring can yield threat intelligence, but it allows the attacker to maintain persistence, exfiltrate data, and pivot to other systems. The scenario requires both containment and investigation, and unrestricted monitoring provides no containment. Unless a deliberate, well-resourced deception operation is authorized, this exposure is unacceptable and fails the containment requirement.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.