mediumMultiple Select
CISM Practice Question: Which THREE are essential steps in incident…
Which THREE are essential steps in incident containment? (Choose three.)
⚠ Common exam trap
The CISM exam often tests the distinction between containment steps (immediate actions to stop the incident) and post-incident activities (like root cause analysis or notification), leading candidates to mistakenly include regulatory notification or root cause analysis as part of containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable compromised accounts
Disabling compromised accounts (C) is an essential containment step because it immediately cuts off the attacker's authenticated access and prevents lateral movement or further data theft using valid credentials. Isolating affected systems (D) is essential containment because it severs network connectivity (e.g., via VLAN change, host firewall block, or endpoint isolation) to stop malware propagation and command-and-control communication while keeping the host available for investigation. Preserving forensic evidence (E) is essential during containment because volatile data (memory, network connections, logs) and disk artifacts must be captured before remediation actions like reimaging or rebooting destroy them, supporting later root cause analysis and legal proceedings. Root cause analysis (A) is not a containment step but a later post-incident activity in the lessons-learned/recovery phase, and notifying external regulators (B) is a communication/notification obligation that typically follows containment and assessment, not a containment action itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Root cause analysis
Why it's wrong here
Root cause analysis is performed during post-incident review after containment and eradication, not while actively limiting damage. It is tempting because understanding the vector feels urgent and informs containment decisions, so it would be correct in the lessons-learned phase following recovery.
- ✗
Notify external regulators
Why it's wrong here
Notification to regulators occurs after containment and is part of the communication and compliance process.
- ✓
Disable compromised accounts
Why this is correct
Disabling compromised accounts severs the attacker's authenticated access path, directly satisfying containment by halting further use of valid credentials. This prevents ongoing unauthorised activity while other systems are assessed, and preserves the account's data for later forensic examination rather than deleting it.
- ✓
Isolate affected systems
Why this is correct
Isolating affected systems cuts network connectivity to the compromised hosts, directly satisfying containment by stopping lateral spread and command-and-control traffic. This limits blast radius while allowing the hosts to remain powered for memory capture and investigation, rather than shutting them down and losing volatile evidence.
- ✓
Preserve forensic evidence
Why this is correct
Preserving forensic evidence captures volatile data such as memory, logs and network state before containment actions alter or destroy it. This satisfies the containment requirement to maintain evidentiary integrity, enabling root cause analysis, attribution and any subsequent legal or disciplinary proceedings without contaminating the artefacts.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.