Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: The lead security analyst at a mid-sized…

You are the lead security analyst at a mid-sized financial services firm. At 2:15 PM, the SIEM alerts on multiple failed login attempts from an external IP address against the VPN gateway. The attempts stopped at 2:20 PM, but at 2:30 PM, a user reports that their account was used to send a phishing email to internal employees. You confirm that the user's account has been compromised. The CEO asks for an immediate update. What should be your FIRST action according to the incident response framework your company follows (based on NIST SP 800-61)?

⚠ Common exam trap

Test-takers frequently confuse containment actions (like isolation) with the first step, but NIST SP 800-61 mandates validation and scoping before any containment to ensure the response is appropriate and not disruptive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Validate the incident and assess its scope and impact.

According to NIST SP 800-61, the first phase of incident response is preparation, followed by detection and analysis. The SIEM alert and user report indicate a potential incident, but you must first validate the incident and assess its scope and impact before taking containment, eradication, or recovery actions. This ensures that resources are not wasted on a false positive and that the response is proportional to the actual threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Preserve forensic evidence by creating a disk image of the user's workstation.

    Why it's wrong here

    Preserving forensic evidence by creating a disk image is a critical step in the incident response lifecycle, but it is typically performed after the incident has been validated and initial containment strategies are underway. Rushing to image a disk without confirming an actual incident could lead to wasted time and resources on a false positive, potentially delaying more urgent investigative or containment actions. This action is part of the eradication or recovery phase, not initial detection.

  • Validate the incident and assess its scope and impact.

    Why this is correct

    Validating the incident is the crucial first step, confirming that a genuine security event has occurred rather than a false alarm or operational issue. Concurrently, assessing the scope identifies affected systems and data, while impact assessment quantifies potential damage, guiding the prioritization of subsequent response activities. This dual action ensures resources are effectively allocated and prevents unnecessary disruption from non-incidents, establishing a solid foundation for the entire response process.

  • Immediately notify the legal and compliance teams.

    Why it's wrong here

    Immediately notifying legal and compliance teams without first validating the incident and assessing its preliminary scope can be premature and counterproductive. Such early communication risks causing undue alarm, spreading unconfirmed information, or initiating legal processes based on an unverified event. While crucial for regulatory adherence, these notifications are typically triggered once an incident is confirmed and its potential legal or compliance implications are better understood.

  • Isolate the compromised workstation from the network.

    Why it's wrong here

    Isolating a potentially compromised workstation is a key containment strategy to prevent further propagation of an attack, but it should not precede incident validation. Performing isolation without confirming the incident could unnecessarily disrupt legitimate business operations or critical services if the alert proves to be a false positive. The incident response process prioritizes confirming the threat before implementing disruptive containment measures to ensure actions are targeted and justified.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.