easyMultiple Choice
Master Incident Containment for CISM Exam
An organization's incident response plan includes a step to 'contain the incident.' Which of the following actions is an example of containment?
Quick Answer
Disconnecting an infected workstation from the network is the correct example of incident containment because it immediately isolates the compromised system, halting the spread of malware and preventing unauthorized lateral movement to other hosts. Containment is a critical step in the NIST SP 800-61 incident response lifecycle, focused strictly on limiting scope and impact before any eradication or recovery begins—it is not about investigation or remediation. On the Certified Information Security Manager CISM exam, this concept tests your ability to distinguish containment from other response phases like eradication or evidence collection; a common trap is confusing containment with remediation actions such as patching or scanning. Remember the memory tip: “Isolate before you eradicate”—containment is the firewall that stops the fire from spreading, not the hose that puts it out.
⚠ Common exam trap
ISACA often tests the distinction between containment, eradication, and recovery, and the trap here is that candidates mistake 'removing malware' (eradication) or 'restoring from backup' (recovery) for containment, because they focus on fixing the problem rather than stopping its spread first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnecting an infected workstation from the network
Disconnecting an infected workstation from the network is a classic containment action because it immediately isolates the compromised system, preventing the spread of malware or unauthorized lateral movement to other hosts. Containment focuses on limiting the scope and impact of an incident, not on remediation or investigation. This step aligns with the NIST SP 800-61 incident response lifecycle, where containment is performed before eradication and recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnecting an infected workstation from the network
Why this is correct
Disconnecting the infected workstation from the network isolates it, preventing lateral movement and further compromise while remediation proceeds. This satisfies the containment step by limiting the incident's scope, distinct from eradication (removing malware) or recovery (restoring service).
- ✗
Restoring data from backup
Why it's wrong here
Restoring data from backup is recovery, returning operations to normal after the threat is removed. It is tempting because it follows containment in the lifecycle, and would be correct once containment and eradication are complete and systems must be brought back online.
- ✗
Analyzing log files to determine the attack vector
Why it's wrong here
Log analysis establishes the attack vector, which belongs to the identification and investigation phases, not containment. It is tempting because scoping the intrusion guides later eradication, and in a threat-hunting or post-incident review scenario this analysis would be the correct activity.
- ✗
Removing malware from the system
Why it's wrong here
Removing malware is eradication, eliminating the threat from the host, not containment. It is tempting because both occur early and often on the same system, yet eradication would be correct once the incident is isolated and the malicious code must be deleted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the PRIMARY goal of incident containment?
easy- A.To gather evidence for prosecution.
- B.To recover systems to normal operation.
- C.To identify the root cause.
- ✓ D.To prevent further damage and limit the scope of the incident.
Why D: The primary goal of incident containment is to stop the incident from spreading and to limit the scope of damage. This is the immediate priority because, without containment, the attacker may continue to compromise additional systems, exfiltrate data, or escalate privileges. Options A, B, and C are important subsequent steps but are secondary to the urgent need to halt the incident's progression.
Variation 2. Which TWO of the following are primary goals of the containment phase in incident response? (Select TWO)
easy- A.Restore normal business operations
- B.Eradicate the root cause of the incident
- C.Preserve evidence for legal proceedings
- ✓ D.Prevent the incident from spreading to other systems
- ✓ E.Limit the scope and impact of the incident
Why D: Option D is correct because the containment phase is specifically designed to stop an active incident from propagating to additional hosts, accounts, or network segments, for example by isolating compromised endpoints, segmenting VLANs, or blocking malicious C2 traffic at the firewall. Option E is correct because containment also aims to limit the scope and impact of the incident, minimizing damage to data, services, and other assets while the incident is still being actively managed. Options A, B, and C do not belong here: restoring normal business operations is the goal of the recovery phase, eradicating the root cause is the goal of the eradication phase, and while evidence preservation is important throughout incident response, it is not one of the two primary goals of containment itself.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.