Isaca
CISM · Question #532
Which of the following should be done FIRST after a ransomware incident has been successfully contained?
The correct answer is B. Conduct forensic analysis. Once containment is achieved, the priority is to conduct forensic analysis to preserve evidence, determine the scope and root cause of the attack, and inform subsequent recovery efforts before restoring systems or drawing broader lessons.
Submitted by renata2k· Apr 18, 2026Information Security Incident Management
Question
Which of the following should be done FIRST after a ransomware incident has been successfully contained?
Options
- ANotify relevant stakeholders.
- BConduct forensic analysis.
- CPerform lessons learned.
- DRestore impacted systems.
How the community answered
(24 responses)- A13% (3)
- B79% (19)
- C4% (1)
- D4% (1)
Explanation
Once containment is achieved, the priority is to conduct forensic analysis to preserve evidence, determine the scope and root cause of the attack, and inform subsequent recovery efforts before restoring systems or drawing broader lessons.
Topics
#Incident Response Process#Forensic Analysis#Ransomware#Containment Phase
Community Discussion
No community discussion yet for this question.