nerdexam
Isaca

CISM · Question #211

Which of the following should be given the HIGHEST priority during recovery after a cybersecurity incident?

The correct answer is A. Bringing restored systems online. The recovery phase exists specifically to restore business operations, making bringing restored systems back online the highest priority. Forensic evidence preservation (D) is a containment-phase activity and should already be complete before recovery begins. Identifying…

Submitted by marco_it· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be given the HIGHEST priority during recovery after a cybersecurity incident?

Options

  • ABringing restored systems online
  • BPreparing a report for senior management
  • CIdentifying exploited vulnerabilities
  • DPreserving forensic evidence

How the community answered

(60 responses)
  • A
    82% (49)
  • B
    5% (3)
  • C
    2% (1)
  • D
    12% (7)

Explanation

The recovery phase exists specifically to restore business operations, making bringing restored systems back online the highest priority. Forensic evidence preservation (D) is a containment-phase activity and should already be complete before recovery begins. Identifying exploited vulnerabilities (C) belongs to the post-incident analysis phase. Preparing a management report (B) is administrative and does not drive recovery outcomes. Delaying system restoration while focusing on reporting or analysis extends business disruption unnecessarily.

Topics

#Incident recovery#System restoration#Business continuity#Prioritization

Community Discussion

No community discussion yet for this question.

Full CISM Practice