nerdexam
Isaca

CISM · Question #380

Which of the following should be the FIRST action in response to a ransomware attack?

The correct answer is C. Disconnect the impacted devices from the network.. The immediate priority in a ransomware attack is containment - disconnecting affected devices from the network stops the ransomware from spreading laterally to other systems and encrypting more data. This is the first step in any incident response containment phase. Contacting th

Submitted by dimitri_ru· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be the FIRST action in response to a ransomware attack?

Options

  • AContact the forensics team.
  • BCheck the availability of backups.
  • CDisconnect the impacted devices from the network.
  • DNotify senior management of the event.

How the community answered

(19 responses)
  • A
    11% (2)
  • C
    84% (16)
  • D
    5% (1)

Explanation

The immediate priority in a ransomware attack is containment - disconnecting affected devices from the network stops the ransomware from spreading laterally to other systems and encrypting more data. This is the first step in any incident response containment phase. Contacting the forensics team (A) and notifying management (D) are important but secondary to stopping the spread. Checking backup availability (B) is critical for recovery planning but comes after containment. Failing to isolate infected systems first can result in the entire network being compromised, dramatically worsening the incident.

Topics

#Ransomware#Incident Response#Containment#Network Security

Community Discussion

No community discussion yet for this question.

Full CISM Practice