nerdexam
Isaca

CISM · Question #507

Which of the following should be done FIRST when a system is infected with malware?

The correct answer is A. Isolate the affected system from the network. The first priority when malware is detected is containment: isolating the infected system from the network prevents lateral movement and stops the malware from spreading to other systems, exfiltrating data, or communicating with a command-and-control server. All other actions…

Submitted by kwame.gh· Apr 18, 2026Information Security Incident Management

Question

Which of the following should be done FIRST when a system is infected with malware?

Options

  • AIsolate the affected system from the network.
  • BReview the firewall logs for suspicious events.
  • CReport the infection to the vendor for further investigation.
  • DDetermine the data loss on the affected system.

How the community answered

(32 responses)
  • A
    78% (25)
  • B
    3% (1)
  • C
    6% (2)
  • D
    13% (4)

Explanation

The first priority when malware is detected is containment: isolating the infected system from the network prevents lateral movement and stops the malware from spreading to other systems, exfiltrating data, or communicating with a command-and-control server. All other actions - reviewing firewall logs (B), engaging the vendor (C), or assessing data loss (D) - are important but secondary. Acting on evidence before containment allows the threat to continue spreading, worsening the impact.

Topics

#Malware infection#Incident response#Containment#System isolation

Community Discussion

No community discussion yet for this question.

Full CISM Practice