Courseiva
mediumMultiple Select

CISM Practice Question: Which THREE are essential steps in incident…

Which THREE are essential steps in incident containment? (Choose three.)

⚠ Common exam trap

The CISM exam often tests the distinction between containment steps (immediate actions to stop the incident) and post-incident activities (like root cause analysis or notification), leading candidates to mistakenly include regulatory notification or root cause analysis as part of containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable compromised accounts

Disabling compromised accounts (C) is an essential containment step because it immediately cuts off the attacker's authenticated access and prevents lateral movement or further data theft using valid credentials. Isolating affected systems (D) is essential containment because it severs network connectivity (e.g., via VLAN change, host firewall block, or endpoint isolation) to stop malware propagation and command-and-control communication while keeping the host available for investigation. Preserving forensic evidence (E) is essential during containment because volatile data (memory, network connections, logs) and disk artifacts must be captured before remediation actions like reimaging or rebooting destroy them, supporting later root cause analysis and legal proceedings. Root cause analysis (A) is not a containment step but a later post-incident activity in the lessons-learned/recovery phase, and notifying external regulators (B) is a communication/notification obligation that typically follows containment and assessment, not a containment action itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Root cause analysis

    Why it's wrong here

    Root cause analysis is performed during post-incident review after containment and eradication, not while actively limiting damage. It is tempting because understanding the vector feels urgent and informs containment decisions, so it would be correct in the lessons-learned phase following recovery.

  • ✗

    Notify external regulators

    Why it's wrong here

    Notification to regulators occurs after containment and is part of the communication and compliance process.

  • ✓

    Disable compromised accounts

    Why this is correct

    Disabling compromised accounts severs the attacker's authenticated access path, directly satisfying containment by halting further use of valid credentials. This prevents ongoing unauthorised activity while other systems are assessed, and preserves the account's data for later forensic examination rather than deleting it.

  • ✓

    Isolate affected systems

    Why this is correct

    Isolating affected systems cuts network connectivity to the compromised hosts, directly satisfying containment by stopping lateral spread and command-and-control traffic. This limits blast radius while allowing the hosts to remain powered for memory capture and investigation, rather than shutting them down and losing volatile evidence.

  • ✓

    Preserve forensic evidence

    Why this is correct

    Preserving forensic evidence captures volatile data such as memory, logs and network state before containment actions alter or destroy it. This satisfies the containment requirement to maintain evidentiary integrity, enabling root cause analysis, attribution and any subsequent legal or disciplinary proceedings without contaminating the artefacts.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.