mediumMultiple Choice
CISM Practice Question: During incident response, a team discovers that a…
During incident response, a team discovers that a phishing email successfully compromised a user's credentials. Which containment strategy would BEST limit further damage?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user account
Disabling the user account immediately stops any ongoing misuse of the compromised credentials, preventing the attacker from accessing additional resources. Option A is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable the user account
Why this is correct
Disabling the account immediately revokes the compromised credentials' ability to authenticate, cutting off the attacker's access path while investigation continues. This contains the breach at its entry point, preventing lateral movement or further data theft using that identity.
- ✗
Restore the user's system from a backup
Why it's wrong here
Restoring from backup recovers files but leaves the compromised credentials valid, so the attacker retains access. It is tempting as ransomware recovery, where restoring clean data is the correct response, but here credential revocation and session invalidation are needed first.
- ✗
Block the sender's IP address at the firewall
Why it's wrong here
Blocking the sender's IP at the firewall stops only that source; the attacker already holds valid credentials and can authenticate from any address. It is tempting because IP blocking is a routine containment control for ongoing external attacks, and would be correct against brute-force or scanning traffic rather than a successful credential compromise.
- ✗
Change all user passwords
Why it's wrong here
Resetting every user's password is disruptive and does not revoke the attacker's active session tokens or refresh tokens, so the compromised account remains usable. It is tempting because bulk credential rotation is a standard remediation after confirmed credential theft, but it belongs to eradication and recovery, not immediate containment of the phishing foothold.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.