nerdexam
Isaca

CISM · Question #114

An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done FIRST?

The correct answer is C. Invoke the incident response plan.. When threat actors exploit a critical vulnerability, the first action should be to invoke the incident response plan to ensure a structured and coordinated response.

Submitted by packet_pusher· Apr 18, 2026Information Security Incident Management

Question

An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done FIRST?

Options

  • ANotify senior management.
  • BPrevent access to the application.
  • CInvoke the incident response plan.
  • DInstall additional application controls.

How the community answered

(43 responses)
  • A
    12% (5)
  • B
    7% (3)
  • C
    79% (34)
  • D
    2% (1)

Why each option

When threat actors exploit a critical vulnerability, the first action should be to invoke the incident response plan to ensure a structured and coordinated response.

ANotify senior management.

Notifying senior management is an important step within the incident response plan, often occurring after initial assessment and containment.

BPrevent access to the application.

Preventing access to the application (containment) is a critical step in incident response, but it is part of executing the incident response plan, not the very first action before the plan is formally engaged.

CInvoke the incident response plan.Correct

Invoking the incident response plan immediately establishes a structured framework for addressing the confirmed compromise, coordinating necessary actions, and defining roles and responsibilities. This ensures an organized and efficient approach to contain, eradicate, recover from, and post-analyze the incident, preventing chaotic or uncoordinated reactions.

DInstall additional application controls.

Installing additional application controls is part of eradication and recovery, which comes after containment and is guided by the incident response plan.

Concept tested: Incident response plan initiation

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident Response Plan#Incident Management#First Response#Security Incident

Community Discussion

No community discussion yet for this question.

Full CISM Practice