nerdexam
Isaca

CISM · Question #144

Which of the following should be the FIRST consideration for an information security manager after a security incident has been confirmed?

The correct answer is B. Executing containment procedures. Containment is the immediate priority once an incident is confirmed. The goal is to stop the bleeding - prevent the incident from spreading, limit damage, and preserve evidence. Acting before containment (e.g., restoring operations or hunting for root cause) can allow the…

Submitted by saadiq_pk· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be the FIRST consideration for an information security manager after a security incident has been confirmed?

Options

  • ADeveloping incident reporting criteria
  • BExecuting containment procedures
  • CRestoring business operations
  • DDetermining the root cause

How the community answered

(53 responses)
  • B
    94% (50)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Containment is the immediate priority once an incident is confirmed. The goal is to stop the bleeding - prevent the incident from spreading, limit damage, and preserve evidence. Acting before containment (e.g., restoring operations or hunting for root cause) can allow the attack to propagate further or destroy forensic evidence. Developing reporting criteria (A) is a planning activity done before incidents occur. Restoring operations (C) comes after containment and eradication. Root cause analysis (D) is part of post-incident review. The incident response lifecycle follows: containment → eradication → recovery → lessons learned.

Topics

#Incident Response#Containment Procedures#Incident Management Process

Community Discussion

No community discussion yet for this question.

Full CISM Practice