Courseiva
mediumMultiple ChoiceObjective-mapped

How to Respond to Compromised Credentials: CISM Tips

During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?

Quick Answer

The correct immediate action is to disable the compromised credentials and initiate a forensic investigation. Disabling the credentials is the critical first step because it halts any ongoing unauthorized access, containing the breach in real time, while launching a forensic investigation ensures that the full scope of the intrusion—such as which sensitive data was accessed and how the compromise occurred—can be determined without further risk. On the CISM exam, this scenario tests your understanding of incident response prioritization, specifically the principle that containment (disabling credentials) must precede notification or personnel actions. A common trap is choosing to terminate the contractor immediately, but termination is a human resources decision that can destroy evidence and is premature without forensic clarity. Another trap is alerting the contractor first, which could tip off a potential insider threat or compromise the investigation. Remember the mnemonic: **CIF** — Contain, Investigate, then Forensically confirm before notifying.

⚠ Common exam trap

Many exam-takers confuse 'immediate containment' with 'immediate notification or punitive action', failing to recognize that the first priority in incident management is to stop the bleeding and secure evidence, not to assign blame or notify external parties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable the compromised credentials and initiate forensic investigation.

When compromised credentials are identified during an incident, the immediate priority is to contain the threat by disabling the compromised credentials to prevent further unauthorized access, and then to initiate a forensic investigation to determine the scope, method, and impact of the breach. Option D correctly follows the incident response containment and investigation phases, ensuring that evidence is preserved and the attack vector is understood before any notification or contractual actions are taken.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Notify the client whose data was accessed.

    Why it's wrong here

    Notifying the client should occur after containment and investigation, not immediately, as it may compromise evidence or cause unnecessary panic.

  • Revoke the contractor's access and terminate the contract.

    Why it's wrong here

    While revoking access is a containment step, terminating the contract may be premature and could destroy evidence or lead to legal issues; investigation should come first.

  • Contact the contractor to ask about the activity.

    Why it's wrong here

    Contacting the contractor without first securing evidence may alert the individual and allow them to destroy evidence or flee.

  • Disable the compromised credentials and initiate forensic investigation.

    Why this is correct

    Disabling the credentials stops further unauthorized access immediately, and initiating forensic investigation ensures proper evidence collection and understanding of the incident. This aligns with the containment and investigation phases of incident response.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization uses a SIEM to correlate security events. The SIEM generates an alert for a possible brute-force attack against an admin account. The incident response team reviews the alert and finds that the account is a service account with a known password. What should the team do NEXT?

hard
  • A.Notify the service owner
  • B.Disable the service account
  • C.Investigate the source IP addresses
  • D.Change the password for the service account

Why D: The correct next step is to change the password for the service account because the alert indicates a possible brute-force attack, and a known password represents a compromised credential. Even if the account is a service account, the password must be rotated to prevent unauthorized access. This aligns with the incident response principle of containing the threat by invalidating the compromised authentication factor.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.