nerdexam
Isaca

CISM · Question #105

Which of the following is MOST important to complete during the recovery phase of an incident response process before bringing affected systems back online?

The correct answer is A. Test and verify that compromised systems are clean. During the recovery phase of incident response, it is crucial to test and verify affected systems are clean before bringing them back online to prevent re-infection.

Submitted by katya_ua· Apr 18, 2026Information Security Incident Management

Question

Which of the following is MOST important to complete during the recovery phase of an incident response process before bringing affected systems back online?

Options

  • ATest and verify that compromised systems are clean.
  • BDocument recovery steps for senior management reporting.
  • CRecord and close security incident tickets.
  • DCapture and preserve forensic images of affected systems.

How the community answered

(52 responses)
  • A
    85% (44)
  • B
    4% (2)
  • C
    4% (2)
  • D
    8% (4)

Why each option

During the recovery phase of incident response, it is crucial to test and verify affected systems are clean before bringing them back online to prevent re-infection.

ATest and verify that compromised systems are clean.Correct

Before restoring affected systems, thorough testing and verification are essential to ensure that all malware, backdoors, and rootkits have been completely removed and the vulnerability exploited has been remediated. This step is critical to prevent the immediate re-compromise of systems and ensures the integrity and security of the environment post-incident.

BDocument recovery steps for senior management reporting.

Documenting recovery steps is important for reporting and process improvement, but it does not directly secure the systems before they are brought back online.

CRecord and close security incident tickets.

Recording and closing security incident tickets is an administrative step indicating completion, not a technical action to secure systems.

DCapture and preserve forensic images of affected systems.

Capturing forensic images is part of the containment and eradication phases for evidence preservation, typically done before or during eradication, not primarily during the recovery phase to bring systems back online.

Concept tested: Incident recovery verification

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Response#Recovery Phase#System Remediation#Verification

Community Discussion

No community discussion yet for this question.

Full CISM Practice