CISM · Question #507
Which of the following should be done FIRST when a system is infected with malware?
The correct answer is A. Isolate the affected system from the network. The first priority when malware is detected is containment: isolating the infected system from the network prevents lateral movement and stops the malware from spreading to other systems, exfiltrating data, or communicating with a command-and-control server. All other actions…
Question
Which of the following should be done FIRST when a system is infected with malware?
Options
- AIsolate the affected system from the network.
- BReview the firewall logs for suspicious events.
- CReport the infection to the vendor for further investigation.
- DDetermine the data loss on the affected system.
How the community answered
(32 responses)- A78% (25)
- B3% (1)
- C6% (2)
- D13% (4)
Explanation
The first priority when malware is detected is containment: isolating the infected system from the network prevents lateral movement and stops the malware from spreading to other systems, exfiltrating data, or communicating with a command-and-control server. All other actions - reviewing firewall logs (B), engaging the vendor (C), or assessing data loss (D) - are important but secondary. Acting on evidence before containment allows the threat to continue spreading, worsening the impact.
Topics
Community Discussion
No community discussion yet for this question.