Courseiva
mediumMultiple Choice

How to Respond to Compromised Credentials: CISM Tips

During an incident, the team identifies that a contractor's credentials were used to access sensitive data. Which of the following should be the IMMEDIATE action?

Quick Answer

The correct immediate action is to disable the compromised credentials and initiate a forensic investigation. Disabling the credentials is the critical first step because it halts any ongoing unauthorized access, containing the breach in real time, while launching a forensic investigation ensures that the full scope of the intrusion—such as which sensitive data was accessed and how the compromise occurred—can be determined without further risk. On the CISM exam, this scenario tests your understanding of incident response prioritization, specifically the principle that containment (disabling credentials) must precede notification or personnel actions. A common trap is choosing to terminate the contractor immediately, but termination is a human resources decision that can destroy evidence and is premature without forensic clarity. Another trap is alerting the contractor first, which could tip off a potential insider threat or compromise the investigation. Remember the mnemonic: **CIF** — Contain, Investigate, then Forensically confirm before notifying.

⚠ Common exam trap

Many exam-takers confuse 'immediate containment' with 'immediate notification or punitive action', failing to recognize that the first priority in incident management is to stop the bleeding and secure evidence, not to assign blame or notify external parties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the compromised credentials and initiate forensic investigation.

When compromised credentials are identified during an incident, the immediate priority is to contain the threat by disabling the compromised credentials to prevent further unauthorized access, and then to initiate a forensic investigation to determine the scope, method, and impact of the breach. Option D correctly follows the incident response containment and investigation phases, ensuring that evidence is preserved and the attack vector is understood before any notification or contractual actions are taken.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify the client whose data was accessed.

    Why it's wrong here

    Notification is a legal and contractual obligation triggered after containment, not during active unauthorised access. Notifying the client while the contractor's credentials remain valid leaves the exposure open. Client notification would be correct once access is revoked and the scope of the breach is established.

  • ✗

    Revoke the contractor's access and terminate the contract.

    Why it's wrong here

    Terminating the contract is a legal and commercial step that cannot be executed instantly and does not stop ongoing misuse of the credentials. Revoking access is the containment action. Contract termination belongs to post-incident remediation and vendor management, once the breach is contained and evidence preserved.

  • ✗

    Contact the contractor to ask about the activity.

    Why it's wrong here

    Contacting the contractor first delays containment while compromised credentials remain usable, so access must be revoked immediately. Interviewing the contractor is appropriate later, during evidence gathering, once the account is disabled and the incident is contained.

  • ✓

    Disable the compromised credentials and initiate forensic investigation.

    Why this is correct

    Disabling the compromised contractor credentials immediately halts further unauthorised access to sensitive data, satisfying containment as the priority during an active incident. Forensic investigation then proceeds on preserved evidence without the attacker retaining live access, balancing eradication with evidentiary integrity.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization uses a SIEM to correlate security events. The SIEM generates an alert for a possible brute-force attack against an admin account. The incident response team reviews the alert and finds that the account is a service account with a known password. What should the team do NEXT?

hard
  • A.Notify the service owner
  • B.Disable the service account
  • C.Investigate the source IP addresses
  • ✓ D.Change the password for the service account

Why D: The correct next step is to change the password for the service account because the alert indicates a possible brute-force attack, and a known password represents a compromised credential. Even if the account is a service account, the password must be rotated to prevent unauthorized access. This aligns with the incident response principle of containing the threat by invalidating the compromised authentication factor.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.