Courseiva
easyMultiple Select

CISM Practice Question: During the detection and analysis phase of…

During the detection and analysis phase of incident response, which two activities are essential? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identifying indicators of compromise.

Option A is correct because identifying indicators of compromise (IOCs) — such as unusual network connections, unexpected file hashes, registry changes, or anomalous login patterns — is a core detection and analysis activity that confirms whether an incident has occurred and characterizes the threat. Option E is correct because determining the scope of the incident (which hosts, accounts, data, and network segments are affected, and how far the compromise has spread) is essential during detection and analysis to understand impact and guide containment decisions. Options B, C, and D do not belong here: restoring systems from backup is a recovery-phase (post-containment/eradication) activity, notifying regulatory bodies is typically a post-incident or reporting/coordination activity, and applying security patches is a remediation/eradication or preventive maintenance action rather than part of detection and analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identifying indicators of compromise.

    Why this is correct

    Indicators of compromise are the forensic artefacts—anomalous log entries, unusual network connections, unexpected file hashes—that confirm an incident is occurring. Identifying them during detection and analysis scopes the event, distinguishes malicious activity from benign noise, and drives containment decisions, directly satisfying the phase's requirement to validate and characterise the incident.

  • ✗

    Restoring systems from backup.

    Why it's wrong here

    Restoring systems from backup belongs to eradication and recovery, not detection and analysis; it rebuilds data after the incident's scope is understood. It tempts because backup restoration is genuinely required when destructive malware or ransomware corrupts production data, and recovery cannot proceed until clean images exist.

  • ✗

    Notifying regulatory bodies.

    Why it's wrong here

    Notification to regulators belongs to post-incident activities or containment reporting, not detection and analysis. It tempts because regulatory obligations feel urgent during a breach, but the phase's essential activities are validating the incident and determining its scope and impact.

  • ✗

    Applying security patches.

    Why it's wrong here

    Incorrect: Part of eradication/recovery.

  • ✓

    Determining the scope of the incident.

    Why this is correct

    Determining scope establishes which systems, data and users are affected, letting responders prioritise containment and eradication. Without it, the detection and analysis phase cannot distinguish a contained event from a spreading one, so the incident's true boundaries stay unknown.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.