easyMultiple Choice
Evidence Preservation: Next Step After Isolating Ransomware
During an incident, the incident response team needs to preserve evidence for legal proceedings. Which of the following is the MOST important action to take?
⚠ Common exam trap
Many candidates choose 'Notify law enforcement immediately' because they assume legal proceedings require early police involvement, but the CISM exam emphasizes that evidence preservation and chain of custody must be secured first, and law enforcement notification is a separate decision based on legal counsel and organizational policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a forensic image of affected systems using write-blockers.
Creating a forensic image of affected systems using write-blockers is the most important action because it preserves the original data in a bit-for-bit, unaltered state, ensuring the evidence is admissible in legal proceedings. Write-blockers prevent any write operations to the source drive, maintaining the integrity of the evidence chain of custody. Without a forensically sound image, any subsequent analysis could be challenged as tampered or unreliable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a forensic image of affected systems using write-blockers.
Why this is correct
A forensic image captures a bit-for-bit copy of the affected systems, preserving volatile and non-volatile data in its original state. Write-blockers prevent any modification to the source drive during acquisition, maintaining evidential integrity and chain of custody so the copy is admissible in legal proceedings.
- ✗
Document the incident in a free-form text.
Why it's wrong here
Free-form text lacks the structured metadata, timestamps and chain-of-custody fields that legal proceedings require to authenticate evidence. It is tempting because narrative notes are quick to write during a live incident, and would suit internal post-incident review, but not court-admissible documentation.
- ✗
Take screenshots of system logs.
Why it's wrong here
Screenshots are secondary copies that alter nothing but capture only visible content, lacking the integrity and completeness of a forensic image; volatile memory and original media must be captured first. It is tempting because screenshots are quick and familiar, and would be correct for documenting a visible configuration state when full imaging is impractical.
- ✗
Notify law enforcement immediately.
Why it's wrong here
Immediate notification can trigger legal processes before evidence is secured, and law enforcement involvement follows organisational and legal guidance, not the responder's first action. It is tempting because legal proceedings are mentioned, and it would be correct once evidence preservation and internal escalation are complete.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.