CISM · Question #521
Which of the following should be done FIRST once a cybersecurity attack has been confirmed?
The correct answer is A. Isolate the affected system. The first action after confirming a cybersecurity attack is to isolate the affected system. This helps prevent the spread of the attack to other systems, containing the incident and minimizing further damage. Once the system is isolated, other actions such as severity…
Question
Which of the following should be done FIRST once a cybersecurity attack has been confirmed?
Options
- AIsolate the affected system.
- BSeverity criteria
- CRoot cause analysis
- DRisk appetite
How the community answered
(34 responses)- A88% (30)
- B6% (2)
- C3% (1)
- D3% (1)
Explanation
The first action after confirming a cybersecurity attack is to isolate the affected system. This helps prevent the spread of the attack to other systems, containing the incident and minimizing further damage. Once the system is isolated, other actions such as severity assessment, root cause analysis, and addressing risk appetite can follow.
Topics
Community Discussion
No community discussion yet for this question.