CISM · Question #144
Which of the following should be the FIRST consideration for an information security manager after a security incident has been confirmed?
The correct answer is B. Executing containment procedures. Containment is the immediate priority once an incident is confirmed. The goal is to stop the bleeding - prevent the incident from spreading, limit damage, and preserve evidence. Acting before containment (e.g., restoring operations or hunting for root cause) can allow the…
Question
Which of the following should be the FIRST consideration for an information security manager after a security incident has been confirmed?
Options
- ADeveloping incident reporting criteria
- BExecuting containment procedures
- CRestoring business operations
- DDetermining the root cause
How the community answered
(53 responses)- B94% (50)
- C2% (1)
- D4% (2)
Explanation
Containment is the immediate priority once an incident is confirmed. The goal is to stop the bleeding - prevent the incident from spreading, limit damage, and preserve evidence. Acting before containment (e.g., restoring operations or hunting for root cause) can allow the attack to propagate further or destroy forensic evidence. Developing reporting criteria (A) is a planning activity done before incidents occur. Restoring operations (C) comes after containment and eradication. Root cause analysis (D) is part of post-incident review. The incident response lifecycle follows: containment → eradication → recovery → lessons learned.
Topics
Community Discussion
No community discussion yet for this question.