nerdexam
Isaca

CISA · Question #1

When an intrusion into an organization's network is detected, which of the following should be done FIRST?

The correct answer is B. Identify nodes that have been compromised.. Upon detecting a network intrusion, the immediate priority is to identify the scope of the compromise by determining which nodes have been affected.

Submitted by klara.se· Apr 18, 2026Protection of Information Assets

Question

When an intrusion into an organization's network is detected, which of the following should be done FIRST?

Options

  • AContact law enforcement.
  • BIdentify nodes that have been compromised.
  • CBlock all compromised network nodes.
  • DNotify senior management

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    89% (24)
  • C
    7% (2)

Why each option

Upon detecting a network intrusion, the immediate priority is to identify the scope of the compromise by determining which nodes have been affected.

AContact law enforcement.

Contacting law enforcement is an important step in incident response but typically follows initial assessment and containment, as concrete information is needed.

BIdentify nodes that have been compromised.Correct

Before taking any containment or notification actions, it is crucial to understand the extent of the breach. Identifying compromised nodes allows the organization to accurately assess the impact, determine the attacker's foothold, and plan appropriate incident response steps effectively.

CBlock all compromised network nodes.

Blocking nodes prematurely without full identification could disrupt critical services or alert the attacker, hindering further investigation and eradication efforts.

DNotify senior management

Notifying senior management is essential for stakeholder awareness but should occur after initial assessment to provide them with a more accurate picture of the situation.

Concept tested: Incident response first steps, scope identification

Source: https://learn.microsoft.com/en-us/security/operations/incident-response-overview

Topics

#Incident Response#Intrusion Detection#Security Incident Management#Cyber Incident Response

Community Discussion

No community discussion yet for this question.

Full CISA Practice