nerdexam
Isaca

CISM · Question #399

After a recovery from a successful malware attack, instances of the malware continue to be discovered. Which phase of incident response was not successful?

The correct answer is A. Eradication. The eradication phase was not successful because instances of the malware continued to be discovered after the recovery. This phase should have ensured that the malware was completely removed from the affected systems and that any vulnerabilities were addressed to prevent

Submitted by kim_seoul· Apr 18, 2026Information Security Incident Management

Question

After a recovery from a successful malware attack, instances of the malware continue to be discovered. Which phase of incident response was not successful?

Options

  • AEradication
  • BLessons learned review
  • CIncident declaration
  • DRecovery

How the community answered

(27 responses)
  • A
    93% (25)
  • B
    4% (1)
  • D
    4% (1)

Explanation

The eradication phase was not successful because instances of the malware continued to be discovered after the recovery. This phase should have ensured that the malware was completely removed from the affected systems and that any vulnerabilities were addressed to prevent

Topics

#Incident Response#Eradication#Malware#Incident Management Phases

Community Discussion

No community discussion yet for this question.

Full CISM Practice