Courseiva
mediumMultiple ChoiceObjective-mapped

Next Step After Ransomware Containment: Create Forensic Image

After a ransomware incident, the incident response team contains the spread and begins eradication. The team discovers that the ransomware encrypted files on a file server and also deleted shadow copies. Which of the following should the team do NEXT to support recovery?

Quick Answer

The answer is to create a forensic image of the file server and affected endpoints. After containment and eradication, the next step to support recovery is preserving a bit-for-bit copy of the encrypted systems because recovery actions like restoring from backups or running decryption tools can overwrite critical artifacts, including the ransomware binary, encryption keys, and evidence of the attack vector. On the CISM exam, this tests your understanding of the incident response phase where evidence collection precedes recovery, ensuring root cause analysis and legal admissibility are not compromised. A common trap is to jump directly to data restoration, but the exam emphasizes that forensic imaging must occur before any recovery step to avoid spoliation. Remember the mnemonic: ICE — Isolate, Contain, then Evidence before recovery.

⚠ Common exam trap

It's easy for candidates to assume recovery (restoring backups) is the immediate next step, but CISM emphasizes that evidence preservation must precede any recovery action to support forensic analysis and legal proceedings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a forensic image of the file server and affected endpoints.

After containment and eradication, the priority is to preserve evidence for root cause analysis and potential legal action. Creating a forensic image of the file server and affected endpoints captures the ransomware artifacts, encryption keys, and system state before any recovery actions that could overwrite critical data. This aligns with the CISM incident management phase of 'lessons learned' and ensures the team can determine the attack vector and prevent recurrence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restore the encrypted files from the most recent backup.

    Why it's wrong here

    Restoring without preserving evidence may destroy forensic artifacts.

  • Create a forensic image of the file server and affected endpoints.

    Why this is correct

    Preserving evidence is essential before any recovery actions.

  • Attempt to decrypt the files using available decryption tools.

    Why it's wrong here

    Decryption attempts may alter data and hinder investigation.

  • Notify law enforcement immediately.

    Why it's wrong here

    Law enforcement notification is important but not the immediate next step for recovery.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. After detecting a ransomware infection on a file server, the incident response team performs containment and eradication. Which step should be prioritized during the recovery phase to minimize business impact?

medium
  • A.Contact the attackers to negotiate a decryption key
  • B.Reimage all servers in the same network segment
  • C.Identify and patch the vulnerability used for entry
  • D.Restore data from verified clean backups

Why D: Restoring data from clean backups is the most direct way to recover operations without paying ransom. Identifying the vulnerability (B) is part of eradication, not recovery. Negotiating with attackers (A) is discouraged. Reimaging all servers (D) may be excessive and cause more downtime.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.