Courseiva
Incident Management →mediumMultiple Choice

CISM Incident Management Practice Question

During containment of a confirmed intrusion, the incident response manager must decide whether to immediately rebuild the compromised server or first acquire volatile data. Legal counsel has signalled that litigation is likely. Which of the following is the BEST course of action?

⚠ Common exam trap

The trap here is treating evidence preservation and service restoration as mutually exclusive, when the correct sequence is to capture volatile data first and then rebuild.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture volatile data in order of volatility, then rebuild the server from a known-good image

Forensic soundness requires capturing the most volatile data first because memory and connection state are lost on shutdown or rebuild. Once that evidence is preserved, the server can be rebuilt from a known-good image to restore service. This sequence respects the litigation hold implied by legal counsel while still meeting the organisation's recovery objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Capture volatile data in order of volatility, then rebuild the server from a known-good image

    Why this is correct

    Volatile artefacts disappear on shutdown, so they must be collected first, following the order-of-volatility principle. Once memory, connections, and process state are preserved, the server can be rebuilt from trusted media to restore service. This satisfies both the forensic and legal requirements and the business need to recover, which is the balanced outcome the scenario demands.

  • ✗

    Rebuild the server immediately to restore service, then document what was observed before the rebuild

    Why it's wrong here

    Restoring service first destroys volatile evidence such as memory-resident malware, active network connections, and running processes. Written recollections are not a substitute for forensic artefacts and would likely be challenged in litigation. This approach prioritises availability over the organisation's legal and investigative obligations, which is inappropriate once counsel has indicated litigation is probable.

  • ✗

    Leave the server running untouched until the external forensic firm arrives several days later

    Why it's wrong here

    Keeping a compromised server online prolongs attacker access, allows further lateral movement, and risks evidence being altered by the attacker or by normal system activity. Waiting days also extends business downtime unnecessarily. Preservation does not require leaving the system exposed; volatile data should be captured promptly and the system then isolated or rebuilt.

  • ✗

    Shut down the server immediately to preserve its current state for investigators

    Why it's wrong here

    A graceful shutdown wipes memory and terminates active connections, destroying exactly the volatile evidence most valuable in an intrusion investigation. Powering off also prevents collection of running-process and network artefacts. Shutdown is appropriate only after volatile data has been captured or when the system poses an imminent physical or network threat that cannot be contained otherwise.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.