nerdexam
Isaca

CISM · Question #508

Which of the following should occur NEXT after a successful malware attack in one segment of an organization's network has been confirmed and contained?

The correct answer is D. Eradication. The incident response lifecycle after identification is: Containment → Eradication → Recovery → Lessons Learned. The question states the incident has already been confirmed (identification done) and contained. The next logical step is eradication - removing the malware, closing…

Submitted by carter_n· Apr 18, 2026Information Security Incident Management

Question

Which of the following should occur NEXT after a successful malware attack in one segment of an organization's network has been confirmed and contained?

Options

  • ARecovery
  • BIncident declaration
  • CLessons learned review
  • DEradication

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    7% (2)
  • D
    89% (24)

Explanation

The incident response lifecycle after identification is: Containment → Eradication → Recovery → Lessons Learned. The question states the incident has already been confirmed (identification done) and contained. The next logical step is eradication - removing the malware, closing the attack vector, and cleaning affected systems. Attempting recovery before eradication risks reinfection. Incident declaration (B) should have occurred earlier during identification. Lessons learned (C) comes last. Recovery (A) follows eradication, not containment.

Topics

#Incident Response Lifecycle#Containment#Eradication#Malware Incident

Community Discussion

No community discussion yet for this question.

Full CISM Practice