Courseiva
mediumMultiple ChoiceObjective-mapped

CISM Practice Question: Your organization is a multinational corporation…

Your organization is a multinational corporation with a hybrid cloud infrastructure, including on-premises data centers and AWS, Azure, and GCP environments. You have a distributed incident response team and a central SIEM that aggregates logs from all sources. You are the incident manager on duty when an alert fires indicating that a high-privilege user account (a domain admin) has been observed logging in from an IP address in a country where the company has no operations, at 3:00 AM local time. Subsequent investigation reveals that the same account also has a successful logon from the corporate headquarters at the same time, which is geographically impossible. The SIEM shows a single event for the suspicious logon, and no other indicators of compromise are present. The account has not been used for months. What is the BEST course of action?

⚠ Common exam trap

It's easy for candidates to assume a single anomalous event with no other indicators is a false positive, but CISM emphasizes that credential theft scenarios often present with minimal initial evidence, and the priority is containment (disable account) before investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Immediately disable the account and reset the password, then begin a forensic investigation to determine the scope of compromise.

The simultaneous logon from two geographically impossible locations indicates a classic credential theft and replay attack, likely using a pass-the-hash or token theft technique. Disabling the account and resetting the password immediately stops the attacker's access, which is the highest priority in incident response. A forensic investigation must follow to identify the attack vector (e.g., Kerberos ticket theft, LSASS dump) and assess the scope of compromise, as the absence of other indicators does not rule out lateral movement or persistence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restore the domain controller from a recent backup to ensure any malware is removed.

    Why it's wrong here

    Restoring the DC is drastic and may not remove the threat if the backup is also compromised; containment should come first.

  • Immediately disable the account and reset the password, then begin a forensic investigation to determine the scope of compromise.

    Why this is correct

    Disabling and resetting the account stops any ongoing malicious activity, and investigation can then proceed safely.

  • Contact the employee who owns the account to ask if they recently traveled or used a VPN.

    Why it's wrong here

    This could tip off an attacker if the account is compromised, and it delays containment.

  • Ignore the alert as it is likely a false positive due to SIEM misconfiguration or time zone discrepancy.

    Why it's wrong here

    The impossible travel pattern is a strong indicator of compromise; ignoring it could lead to data breach.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.