nerdexam
Isaca

CISM · Question #19

Which of the following is MOST important to determine following the discovery and eradication of a malware attack?

The correct answer is B. The malware entry path. After a malware attack, identifying the entry path is crucial for understanding how the breach occurred and implementing effective preventative measures.

Submitted by tarun92· Apr 18, 2026Information Security Incident Management

Question

Which of the following is MOST important to determine following the discovery and eradication of a malware attack?

Options

  • AThe creator of the malware
  • BThe malware entry path
  • CThe type of malware involved
  • DThe method of detecting the malware

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    52% (12)
  • C
    13% (3)
  • D
    26% (6)

Why each option

After a malware attack, identifying the entry path is crucial for understanding how the breach occurred and implementing effective preventative measures.

AThe creator of the malware

While understanding the creator of the malware might be interesting for intelligence, it does not directly help in securing the organization against future attacks in the same way knowing the entry path does.

BThe malware entry pathCorrect

Determining the malware entry path (e.g., phishing email, unpatched vulnerability, malicious download) is critical because it reveals the specific security weakness or vector exploited by the attacker. Understanding this allows the organization to close the vulnerability, implement stronger controls, and prevent similar future attacks, thus improving overall security posture.

CThe type of malware involved

Knowing the specific type of malware (e.g., ransomware, spyware) is important for eradication, but understanding *how* it got in is more critical for preventing recurrence than just its classification.

DThe method of detecting the malware

The method of detecting the malware is important for improving future detection capabilities, but identifying the *initial breach vector* (entry path) is more fundamental for preventing the next attack.

Concept tested: Post-incident root cause analysis

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident response#Root cause analysis#Malware prevention#Post-incident activities

Community Discussion

No community discussion yet for this question.

Full CISM Practice