nerdexam
Isaca

CISM · Question #108

Which of the following is MOST important to consider when planning the eradication of a cyberattack?

The correct answer is D. Knowledge about the type and source of the threat. When planning the eradication of a cyberattack, understanding the type and source of the threat is most important as it guides the specific actions needed to remove the threat and its root cause.

Submitted by yousef_jo· Apr 18, 2026Information Security Incident Management

Question

Which of the following is MOST important to consider when planning the eradication of a cyberattack?

Options

  • AThe skills and competencies of the eradication team
  • BThe cost of tools and efforts required for the process
  • CObtain a clean backup of the operating system
  • DKnowledge about the type and source of the threat

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    4% (1)
  • C
    8% (2)
  • D
    76% (19)

Why each option

When planning the eradication of a cyberattack, understanding the type and source of the threat is most important as it guides the specific actions needed to remove the threat and its root cause.

AThe skills and competencies of the eradication team

While team skills are important for execution, knowing the specific threat type is more fundamental for planning the appropriate eradication strategy.

BThe cost of tools and efforts required for the process

Cost is a practical consideration but secondary to understanding how to effectively remove the threat itself.

CObtain a clean backup of the operating system

Obtaining a clean backup is crucial for recovery (restoring systems), but understanding the threat is necessary for eradicating it and its root cause before recovery.

DKnowledge about the type and source of the threatCorrect

Knowledge about the type and source of the threat is paramount for effective eradication because it allows the incident response team to identify the specific malware, vulnerabilities exploited, and attack vectors. This understanding enables targeted remediation, ensuring that all aspects of the compromise are addressed and preventing re-infection by closing the exploited entry points.

Concept tested: Eradication strategy based on threat intelligence

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Response#Eradication#Threat Analysis#Incident Planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice