easyMultiple Choice
Immediate Containment for C2 Incidents — Isolate Host Before Investigation
A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?
⚠ Common exam trap
It's easy for candidates to think notifying law enforcement is the first step, but CISM emphasizes immediate containment (blocking the IP) before escalation or external notification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the IP address at the firewall.
The immediate response to a brute-force attack from a single external IP is to block that IP at the firewall. This stops the attack at the network perimeter, preventing further authentication attempts without affecting legitimate users (assuming the IP is not a known legitimate source). Delaying action could allow the attacker to compromise an account via password guessing, especially since common usernames are being targeted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block the IP address at the firewall.
Why this is correct
Blocking the source IP at the firewall immediately halts the brute-force attempts, satisfying the requirement for an immediate response. It is fast, reversible and low-risk, stopping the attack at the network perimeter while preserving logs for later analysis, unlike disabling accounts or longer-term tuning.
- ✗
Ignore the alert as it is likely a false positive.
Why it's wrong here
The log evidence of repeated failed logins with common usernames from one external IP indicates genuine brute-force activity, so dismissing it as a false positive leaves the web server exposed. Ignoring is tempting because failed logins are common noise, but that applies to isolated attempts, not sustained patterns from a single source.
- ✗
Disable the web server.
Why it's wrong here
Disabling the web server takes a public-facing production service offline, causing an outage that the failed logins themselves have not achieved. It is tempting because it guarantees the attack stops, but that response suits confirmed compromise or active data exfiltration, not unsuccessful authentication attempts that can be blocked at the network edge.
- ✗
Notify law enforcement.
Why it's wrong here
Law enforcement handles prosecution after an incident, not the immediate containment of an active brute-force attempt, and no crime has yet been confirmed. Notification is tempting because external attacks often warrant escalation, but it belongs after internal response and evidence gathering, not as the first analyst action.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.